org.eclipse.californium:scandium@3.0.0-M3 vulnerabilities

  • latest version

    3.11.0

  • latest non vulnerable version

  • first published

    10 years ago

  • latest version published

    2 months ago

  • licenses detected

  • package manager

Direct Vulnerabilities

Known vulnerabilities in the org.eclipse.californium:scandium package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Signature Validation Bypass

org.eclipse.californium:scandium is a library for exchanging data using DTLS over UDP.

Affected versions of this package are vulnerable to Signature Validation Bypass. If the signature is not included in ServerKeyExchange, then the certificate based (x509 and RPK) DTLS handshakes succeeds without verifying the server side's signature on the client side.

How to fix Signature Validation Bypass?

Upgrade org.eclipse.californium:scandium to version 2.6.5, 3.0.0-M4 or higher.

[2.0.0,2.6.5) [3.0.0-M1,3.0.0-M4)