ca.juliusdavies:not-yet-commons-ssl@0.3.9 vulnerabilities
A Java SSL component library
-
latest version
0.3.11
-
first published
13 years ago
-
latest version published
13 years ago
-
licenses detected
- [0,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the ca.juliusdavies:not-yet-commons-ssl package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
ca.juliusdavies:not-yet-commons-ssl is a Java SSL component library. Affected versions of this package are vulnerable to Security Bypass. The package does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. How to fix Security Bypass? A fix was pushed into the |
[0.3.11]
[0.3.9]
|