In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.
References
Link | Resource |
---|---|
https://github.com/TooTallNate/Java-WebSocket/security/advisories/GHSA-gw55-jm4h-x339 | Third Party Advisory |
https://github.com/TooTallNate/Java-WebSocket/security/advisories/GHSA-gw55-jm4h-x339 | Third Party Advisory |
Configurations
History
21 Nov 2024, 04:56
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 6.8
v3 : 9.0 |
References | () https://github.com/TooTallNate/Java-WebSocket/security/advisories/GHSA-gw55-jm4h-x339 - Third Party Advisory |
Information
Published : 2020-05-07 21:15
Updated : 2024-11-21 04:56
NVD link : CVE-2020-11050
Mitre link : CVE-2020-11050
CVE.ORG link : CVE-2020-11050
JSON object : View
Products Affected
java-websocket_project
- java-websocket