Skip to content

[12.10.2] Hotfix & Stable Release

Choose a tag to compare

@divang divang released this 15 Oct 11:29
34debbc

Fixed issues

  • Address a hostname validation vulnerability by securely parsing certificate common names. #2803
    What was fixed: Secure hostname validation is enforced by replacing the vulnerable CN parsing logic in SQLServerCertificateUtils.java, preventing spoofing attacks.
    Who benefits: All users of the SQL Server JDBC driver, especially those relying on TLS for secure connections, benefit from improved certificate validation.