CVE-2020-11050

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
07/05/2020
Last modified:
07/10/2021

Description

In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:java-websocket_project:java-websocket:*:*:*:*:*:*:*:* 1.4.1 (including)