okhttp: certificate pinning bypass
| Package(s): | okhttp | CVE #(s): | CVE-2016-2402 | ||||||||
| Created: | March 1, 2016 | Updated: | March 2, 2016 | ||||||||
| Description: | From the Red Hat bugzilla:
A vulnerability was discovered in OkHttp that allows an attacker to bypass certificate pinning. OkHttp did not validate that the pinned certificate was in the chain to a trusted certificate authority. | ||||||||||
| Alerts: |
| ||||||||||
