Spring Boot
cpe:2.3:a:pivotal_software:spring_boot:*:*:*:*:*:*:*, +1 more
- >= 4.0.0, <= 4.0.5
- >= 3.5.0, <= 3.5.13
- >= 3.4.0, <= 3.4.15
- >= 3.3.0, <= 3.3.18
- >= 2.7.0, <= 2.7.32
A vulnerability exists in Spring Boot's Cassandra auto-configuration, where hostname verification is not performed when establishing an SSL connection to Cassandra. This issue affects Spring Boot versions 4.0.0 through 4.0.5, 3.5.0 through 3.5.13, 3.4.0 through 3.4.15, 3.3.0 through 3.3.18, and 2.7.0 through 2.7.32. Additionally, versions no longer supported are also affected.
The lack of hostname verification in SSL connections to Cassandra could allow for man-in-the-middle attacks, where an attacker could intercept or alter the communication between Spring Boot and the Cassandra database.
Users should upgrade to Spring Boot version 4.0.6, 3.5.14, 3.4.16 (Enterprise Support Only), 3.3.19 (Enterprise Support Only), or 2.7.33 (Enterprise Support Only), depending on their current version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.