OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NSquareup Okhttp
APPSquareup≤ 2.7.3Squareup Okhttp3
APPSquareup3.0.03.0.13.1.03.1.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje
Powiązane podatności
CVE-2023-0833MEDIUM4.7ten sam produkt
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information d...
CVE-2018-20200MEDIUM5.9ten sam produkt
CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate p...
CVE-2018-1000844CRITICAL9.1PL ✓ten sam vendor
XXE w Squareup Retrofit umożliwiające odczyt plików i SSRF
CVE-2015-8969CRITICAL9.8PL ✓ten sam vendor
Command injection w Squareup git-fastclone — wykonanie dowolnych poleceń
CVE-2026-45799HIGH7.5PL ✓ten sam vendor
Wire (gRPC/protobuf): brak walidacji długości pola powoduje crash usługi