ZeroHour

CVE-2020-11050

CVSS 3.1
8.1 high
EPSS
<1%p54
Published
()
Modified
Description

In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.

Vendors
java-websocket project
Products
java-websocket
Weakness
CWE-297, CWE-295
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.