CVE-2018-20200
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application. NOTE: This id is disputed because some parties don't consider this is a vulnerability. Their rationale can be found in https://github.com/square/okhttp/issues/4967
** EN DISPUTA ** CertificatePinner.java en OkHttp desde la versión 3.x hasta la 3.12.0 permite un ataque man-in-the-middle para eludir la fijación de certificados cambiando SSLContext y los valores booleanos mientras enganchan la aplicación. NOTA: Esta identificación es cuestionada porque algunas partes no consideran que sea una vulnerabilidad. Su razón de ser se puede encontrar en https://github.com/square/okhttp/issues/4967.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-18 CVE Reserved
- 2019-04-18 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-09-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-295: Improper Certificate Validation
CAPEC
References (15)
URL | Date | SRC |
---|---|---|
https://cxsecurity.com/issue/WLB-2018120252 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/square/okhttp/commits/master | 2024-05-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Squareup Search vendor "Squareup" | Okhttp Search vendor "Squareup" for product "Okhttp" | >= 3.0.0 <= 3.12.0 Search vendor "Squareup" for product "Okhttp" and version " >= 3.0.0 <= 3.12.0" | - |
Affected
|