[ 
https://issues.apache.org/jira/browse/THRIFT-6086?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jens Geyer resolved THRIFT-6086.
--------------------------------
      Assignee: Jens Geyer
    Resolution: Fixed

> Add peer hostname validation to c_glib TLS client
> -------------------------------------------------
>
>                 Key: THRIFT-6086
>                 URL: https://issues.apache.org/jira/browse/THRIFT-6086
>             Project: Thrift
>          Issue Type: Bug
>          Components: C glib - Library
>            Reporter: Jens Geyer
>            Assignee: Jens Geyer
>            Priority: Major
>             Fix For: 0.24.0
>
>
> thrift_ssl_socket_handle_handshake() called SSL_connect() then 
> thrift_ssl_socket_authorize(), which checked only certificate chain validity 
> (SSL_get_verify_result()). When authorize_peer was NULL (the common case, no 
> custom access manager), the hostname presented in the certificate was never 
> checked against the hostname the client intended to connect to.
> Fixed by calling SSL_set1_host(ssl_socket->ssl, socket->hostname) before 
> SSL_connect() for client-mode sockets (OpenSSL >= 1.0.2), so a hostname 
> mismatch surfaces through the existing SSL_get_verify_result() check.
> *Affects:* c_glib
> *Fixed by:* commit acf2d30bc9, PR #3507; fixed in 0.24.0
> *CWE-297:* Improper Validation of Certificate with Host Mismatch
> *CVSS 4.0:* 9.1 Critical 
> ({{CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N}})
> *Reported by:* discovered internally during a security review (2026-05-21)
> *CVE:* CVE-2026-48144



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to