Home
MEDIUM: 5.0 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:LDefault status
unaffected
4.0.0 (custom) before 4.0.6
affected
3.5.0 (custom) before 3.5.14
affected
3.4.0 (custom) before 3.4.16
affected
3.3.0 (custom) before 3.3.19
affected
2.7.0 (custom) before 2.7.33
affected
Description
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); Cassandra SSL auto-configuration. Versions that are no longer supported are also affected per vendor advisory.
Problem types
CWE-295: Improper Certificate Validation
Product status
4.0.0 (custom) before 4.0.6
3.5.0 (custom) before 3.5.14
3.4.0 (custom) before 3.4.16
3.3.0 (custom) before 3.3.19
2.7.0 (custom) before 2.7.33
References
spring.io/security/cve-2026-40974