GHSA-rghw-6px2-fgwc
MODERATECVE-2021-20328Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issu
- Affected
- >= 3.12.0, <= 3.12.7, >= 3.11.0, <= 3.11.2
- Fixed in
- 3.12.8
- Weakness
- CWE-295
- Published
- 2022-05-24
- Source
- github