CVE Feed

    Dashboard / CVE / CVE-2024-8285

    CVE-2024-8285

    A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify the server's hostname, resulting in an insecure connection. For a successful attack to be performed, the attacker needs to perform a Man-in-the-Middle attack or compromise any external systems, such as DNS or network routing configuration. This issue is considered a high complexity attack, with additional high privileges required, as the attack would need access to the Kroxylicious configuration or a peer system. The result of a successful attack impacts both data integrity and confidentiality.

    Published:Aug 27, 2024
    Last Modified:Nov 20, 2025
    EPS:Aug 30, 2024
    EPSS Score:0.0015
    CVSS Score:5.9

    Affected Products

    Vendor
    Redhat
    Product
    Amq Streams
    Vendor
    Redhat
    Product
    Kroxylicious

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High