org.glassfish.jersey.core:jersey-client@2.15 vulnerabilities

  • latest version

    4.0.0

  • latest non vulnerable version

  • first published

    13 years ago

  • latest version published

    20 days ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.glassfish.jersey.core:jersey-client package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Race Condition

    Affected versions of this package are vulnerable to Race Condition in the HttpUrlConnector class, during initialization of SSL sockets. An attacker can cause the application to ignore custom SSL settings, including mutual authentication, custom key and trust stores, and other security configurations, by initiating concurrent HTTPS connection requests. This may lead to SSLHandshakeException errors in normal situations, and unauthorized trust in insecure servers under specific conditions.

    How to fix Race Condition?

    Upgrade org.glassfish.jersey.core:jersey-client to version 2.46, 3.0.17, 3.1.10, 4.0.0-M2 or higher.

    [,2.46)[3.0.0-M1,3.0.17)[3.1.0-M1,3.1.10)[4.0.0-M1,4.0.0-M2)