CVE Vulnerabilities

CVE-2021-0341

Improper Certificate Validation

Published: Feb 10, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle8.1 (including)8.1 (including)
AndroidGoogle9.0 (including)9.0 (including)
AndroidGoogle10.0 (including)10.0 (including)
AndroidGoogle11.0 (including)11.0 (including)
Red Hat AMQ Streams 2.4.0RedHatokhttp*
Red Hat Data Grid 8.4.2RedHatokhttp*
Red Hat JBoss Enterprise Application Platform Expansion PackRedHatokhttp*
Red Hat OpenShift Dev Spaces 3 ContainersRedHatdevspaces/server-rhel8:3.16-14*
Red Hat Single Sign-On 7RedHatokhttp*
Red Hat Single Sign-On 7.6 for RHEL 7RedHatrh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el7sso*
Red Hat Single Sign-On 7.6 for RHEL 8RedHatrh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el8sso*
Red Hat Single Sign-On 7.6 for RHEL 9RedHatrh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el9sso*
RHEL-8 based Middleware ContainersRedHatrh-sso-7/sso76-openshift-rhel8:7.6-22*

Potential Mitigations

References