In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.
References
Link | Resource |
---|---|
https://github.com/TooTallNate/Java-WebSocket/security/advisories/GHSA-gw55-jm4h-x339 | Third Party Advisory |
Configurations
Information
Published : 2020-05-07 14:15
Updated : 2021-10-07 10:19
NVD link : CVE-2020-11050
Mitre link : CVE-2020-11050
JSON object : View
CWE
CWE-295
Improper Certificate Validation
Products Affected
java-websocket_project
- java-websocket