VendorsSquareupokhttpall versions
Vulnerabilities

Squareup Square OkHttp

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2018-20200
CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application. NOTE: This id is disputed because some parties don't consider this is a vulnerability. Their rationale can be found in https://github.com/square/okhttp/issues/4967
Published 2019-04-18 · Modified
5.9EPSS 0.025
CVE-2016-2402
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.
Published 2017-01-30 · Modified
5.9EPSS 0.022
CVE-2023-0833
Red hat a-mq streams: component version with information disclosure flaw
Published 2023-09-27 · Modified
5.5EPSS 0.004