logo

Database

Insecure digital certificates In com.squareup.okhttp3:okhttp

Description

Improper Certificate Validation in OkHttp OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-NWIJD – Vulnerability | Fluid Attacks Database