Intel

AIKIDO-2025-10434

mariadb is vulnerable to Improper Certificate Validation

Improper Certificate Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

80

High Risk

This Affects:

JSmariadb
0.0.1 - 3.4.2
Fixed in 3.4.3

TL;DR

Affected versions of this package are vulnerable to improper certificate validation when connecting to a MariaDB server. Specifically, the servername parameter is not properly validated during the TLS handshake, resulting in a failure to verify the server's identity. This flaw allows attackers with a valid certificate for a different hostname to impersonate the server, potentially enabling man-in-the-middle (MITM) attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

mariadb is vulnerable to Improper Certificate Validation in versions 0.0.1 - 3.4.2.

How to fix this

Upgrade the mariadb library to the patch version.