Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Man-in-the-Middle vulnerability #9938

Closed
sureshkrishnamoorthy opened this issue Jan 10, 2020 · 1 comment
Closed

Man-in-the-Middle vulnerability #9938

sureshkrishnamoorthy opened this issue Jan 10, 2020 · 1 comment

Comments

@sureshkrishnamoorthy
Copy link

Man-in-the-Middle vulnerability

Software vulnerability checker(Veracode) reports that netty-handler is vulnerable to Man-in-the-Middle attack. Issue description is provided below. Please let us know how to address this.

"netty-handler is vulnerable to man-in-the-middle attacks. The library uses an SSLEngine that does not verify certificate hostnames when establishing connections with clients by default. This allows an attacker to potentially intercept and modify network traffic in a successful man-in-the-middle attack."

Netty version - 4.1.43-FInal

JVM version (e.g. java -version) - 1.8

OS version (e.g. uname -a) - Windows / Unix

@hyperxpro
Copy link
Contributor

Duplicate of #9930

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants