UBUNTU-CVE-2018-20200
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-20200
UBUNTU-CVE-2018-20200
Summary:
Details: ** DISPUTED ** CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application. NOTE: This id is disputed because some parties don't consider this is a vulnerability. Their rationale can be found in https://github.com/square/okhttp/issues/4967.
References: https://ubuntu.com/security/CVE-2018-20200, https://github.com/square/okhttp/issues/4967, https://cxsecurity.com/issue/WLB-2018120252, https://github.com/square/okhttp/commits/master, https://github.com/square/okhttp/releases, https://square.github.io/okhttp/3.x/okhttp/, https://www.cve.org/CVERecord?id=CVE-2018-20200
Affected packages
Package
Name: libokhttp-java
Purl: pkg:deb/ubuntu/libokhttp-java
Affected ranges
Type: ECOSYSTEM
Events:
