On February 5, 2024, we published a Security Bulletin.
When an Apigee API Management proxy connects to a target endpoint or
target server, the proxy does not perform hostname validation for
the certificate presented by the target endpoint or target server by default.
If hostname validation is not enabled using one of the following options,
Apigee proxies connecting to a target endpoint or target server may be at risk for a man-in-the-middle attack by an authorized user. For more information,
see Configuring TLS from Edge
to the backend (Cloud and Private Cloud).
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2024-12-11 UTC."],[],[]]