Spring Boot
cpe:2.3:a:pivotal_software:spring_boot:*:*:*:*:*:*:*, +1 more
- >= 4.0.0, <= 4.0.5
A vulnerability exists in Spring Boot's Elasticsearch auto-configuration when an SSL bundle is used. The issue arises because the configuration fails to verify hostnames while connecting to the Elasticsearch server. This vulnerability affects Spring Boot versions 4.0.0 through 4.0.5.
The lack of hostname verification can lead to man-in-the-middle attacks, where an attacker could intercept and potentially alter the communication between Spring Boot and the Elasticsearch server.
Users should upgrade to Spring Boot version 4.0.6 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.