Intel

AIKIDO-2024-10336

http-server is vulnerable to Selection of Less-Secure Algorithm During Negotiation

Selection of Less-Secure Algorithm During Negotiation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 15, 2024

25

Low Risk

This Affects:

javahttp-server
200 - 274
Fixed in 275
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to a TLS renegotiation attack. This weakness allows attackers to exploit the TLS renegotiation process, potentially enabling man-in-the-middle attacks, where the attacker could intercept or modify encrypted communications between the client and server.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

http-server is vulnerable to Selection of Less-Secure Algorithm During Negotiation in versions 200 - 274.

How to fix this

Upgrade the io.airlift:http-server library to the patch version.