Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-0341

Опубликовано: 10 фев. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Red Hat AMQ Broker 7okhttpNot affected
Red Hat build of Apicurio Registry 2okhttpNot affected
Red Hat build of QuarkusokhttpNot affected
Red Hat Decision Manager 7okhttpOut of support scope
Red Hat Enterprise Linux 8log4j:2/log4jNot affected
Red Hat Enterprise Linux 9log4jNot affected
Red Hat Fuse 7okhttpOut of support scope
Red Hat Integration Camel K 1okhttpWill not fix
Red Hat Integration Camel Quarkus 1okhttpAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2154086okhttp: information disclosure via improperly used cryptographic function

EPSS

Процентиль: 80%
0.01387
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069

CVSS3: 7.5
github
больше 3 лет назад

Square OkHttp can accept the wrong certificate

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость компонента Centralized Thirdparty Jars (OkHttp) средства управления доступом Oracle Access Manager, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 80%
0.01387
Низкий

7.5 High

CVSS3