ZeroHour

CVE-2017-7192

CVSS 3.0
7.5 high
EPSS
2%p78
Published
()
Modified
Description

WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false).

Vendors
starscream project
Products
starscream
Weakness
CWE-295
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.