Lucene search

K
redhatcveRedhat.comRH:CVE-2018-8039
HistoryMar 28, 2020 - 1:54 p.m.

CVE-2018-8039

2020-03-2813:54:32
redhat.com
access.redhat.com
24

EPSS

0.007

Percentile

80.4%

It was discovered that when Apache CXF is configured to use the system property com.sun.net.ssl.internal.www.protocol ,it uses reflection to make the HostnameVerifier work with old com.sun.net.ssl.HostnameVerifier interface. Although the CXF implementation throws an exception, which is caught in the reflection code but it is not properly propagated, this can lead to a man-in-the-middle attack.