Insecure digital certificates In com.squareup.okhttp3:okhttp
Description
Improper Certificate Validation in OkHttp OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 2.7.4, 3.1.2 | ||
maven | 2.7.4, 3.1.2 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6.