CVE-2020-11050 CRITICAL

CVE-2020-11050: Improper Validation of Certificate with Host Mismatch in Java-WebSocket

Vendor Tootallnate
Product Java-WebSocket
Weakness CWE-297
Published May 7, 2020
Last update August 4, 2024

CVSS base score

9.0/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

Description

In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.

Key dates

Disclosure timeline

May 7, 2020 CVE published
August 4, 2024 Record updated