CVE-2020-11050

In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:java-websocket_project:java-websocket:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:56

Type Values Removed Values Added
CVSS v2 : 6.8
v3 : 8.1
v2 : 6.8
v3 : 9.0
References () https://github.com/TooTallNate/Java-WebSocket/security/advisories/GHSA-gw55-jm4h-x339 - Third Party Advisory () https://github.com/TooTallNate/Java-WebSocket/security/advisories/GHSA-gw55-jm4h-x339 - Third Party Advisory

Information

Published : 2020-05-07 21:15

Updated : 2024-11-21 04:56


NVD link : CVE-2020-11050

Mitre link : CVE-2020-11050

CVE.ORG link : CVE-2020-11050


JSON object : View

Products Affected

java-websocket_project

  • java-websocket
CWE
CWE-297

Improper Validation of Certificate with Host Mismatch

CWE-295

Improper Certificate Validation