The vendor explicitly identifies these products as affected by this CVE.
- openshift-pipelines/pipelines-console-plugin-pf5-rhel9 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-console-plugin-rhel8 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-console-plugin-rhel9 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-hub-ui-rhel8 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-hub-ui-rhel9 as a component of OpenShift Pipelines
- mariadb-java-client as a component of Red Hat build of Debezium 3
- keycloak/rhbk-openshift-rhel9 as a component of Red Hat Build of Keycloak
- mariadb-java-client as a component of Red Hat Build of Keycloak
- rhbk/keycloak-rhel9 as a component of Red Hat Build of Keycloak
- mariadb-java-client as a component of Red Hat build of Quarkus
- mariadb-java-client.src as a component of Red Hat Enterprise Linux 10
- Judy.src (mariadb:10.3) as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in MariaDB Connector/J. An active man-in-the-middle (MITM) attacker or hostile server can exploit a vulnerability during the initial connection handshake. When a Java application connects using specific SSL modes without proper certificate configuration, the connector may accept an untrusted self-signed certificate. This allows the MITM to receive the full database password in cleartext before the connection is rejected, leading to sensitive information disclosure.
- Remediation
- When using sslMode verify-ca or verify-full, configure serverSslCert or a trustStore so the JDBC client validates the server certificate before sending credentials. Upgrade to MariaDB Connector/J 2.7.14, 3.3.5, 3.4.3, or 3.5.9 when available in your product update stream.
