1.2.4
1 years ago
2 months ago
Known vulnerabilities in the com.oviva.telematik:epa4all-client package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Improper Certificate Validation due to disabled TLS certificate validation in production environments. An attacker can intercept sensitive SOAP traffic, including patient identifiers, authentication operations, document content, and credential exchanges by presenting an arbitrary TLS certificate on the network path between the service and its backend. How to fix Improper Certificate Validation? Upgrade | [,1.2.2) |
Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature in the discovery document retrieval process via How to fix Improper Verification of Cryptographic Signature? Upgrade | [,1.2.2) |