OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Okhttp | Squareup | * | 2.7.3 (including) |
Okhttp3 | Squareup | 3.0.0 (including) | 3.0.0 (including) |
Okhttp3 | Squareup | 3.0.0-rc1 (including) | 3.0.0-rc1 (including) |
Okhttp3 | Squareup | 3.0.1 (including) | 3.0.1 (including) |
Okhttp3 | Squareup | 3.1.0 (including) | 3.1.0 (including) |
Okhttp3 | Squareup | 3.1.1 (including) | 3.1.1 (including) |