Improper Validation of Certificate with Host Mismatch in Java-WebSocket 1.4.1 and below

Improper Validation of Certificate with Host Mismatch in Java-WebSocket 1.4.1 and below

CVE-2020-11050 · HIGH Severity

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.

Learn more about our Web App Pen Testing.