GHSA-rghw-6px2-fgwc
MODERATECVE-2021-20328Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issu
- Affected
- >= 3.11.0, <= 3.11.2, >= 3.12.0, <= 3.12.7, = 4.2.0, >= 4.1.0, <= 4.1.1, >= 4.0.0, <= 4.0.5
- Fixed in
- 3.11.3
- Weakness
- CWE-295
- Published
- 2022-05-24
- Source
- github