CVE-2024-8285

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Aug 30, 2024
Updated: Sep 3, 2024
CWE ID 297

Summary

CVE-2024-8285 is a vulnerability affecting Kroxylicious that occurs due to improper verification of an upstream Kafka server's hostname during a TLS-secured connection. This flaw can enable an attacker to conduct a Man-in-the-Middle attack, particularly if they compromise external systems such as DNS or network configurations. The attack requires high privileges and user interaction, making it complex, while potentially compromising both data integrity and confidentiality. To mitigate this risk, organizations should ensure proper hostname validation in their Kroxylicious configuration and monitor for suspicious network activity. The vulnerability is rated with a base severity of high (7.3) according to the CVSS scoring system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share