Description
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069
Published: 2021-02-10
Score: 7.5 High
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-2960 In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069
Github GHSA Github GHSA GHSA-3cqm-mf7h-prrj Square OkHttp can accept the wrong certificate
History

Sat, 14 Sep 2024 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Devspaces
CPEs cpe:/a:redhat:openshift_devspaces:3::el8
Vendors & Products Redhat openshift Devspaces

Subscriptions

Google Android
Redhat Amq Streams Jboss Data Grid Jbosseapxp Openshift Devspaces Red Hat Single Sign On Rhosemc
cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2024-08-03T15:40:00.192Z

Reserved: 2020-11-06T00:00:00.000Z

Link: CVE-2021-0341

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-10T17:15:22.037

Modified: 2024-11-21T05:42:32.723

Link: CVE-2021-0341

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-02-10T00:00:00Z

Links: CVE-2021-0341 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses