CVE-2020-11050

In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:java-websocket_project:java-websocket:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-05-07 21:15

Updated : 2024-02-28 17:47


NVD link : CVE-2020-11050

Mitre link : CVE-2020-11050

CVE.ORG link : CVE-2020-11050


JSON object : View

Products Affected

java-websocket_project

  • java-websocket
CWE
CWE-295

Improper Certificate Validation

CWE-297

Improper Validation of Certificate with Host Mismatch