Intel

AIKIDO-2025-10029

grpc-okhttp is vulnerable to Improper Certificate Validation

Improper Certificate ValidationCVE-2021-0341 Published Jan 20, 2025

75

High Risk

This Affects:

JAVAgrpc-okhttp
0.7.0 - 1.68.2
Fixed in 1.68.3
1.69.0 - 1.69.0
Fixed in 1.69.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package fail to properly validate security certificates. In the verifyHostName method of OkHostnameVerifier.java, a flaw in cryptographic implementation may allow acceptance of certificates for incorrect domains when using non-ASCII subjects. This vulnerability can lead to remote information disclosure without requiring user interaction or additional execution privileges.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

grpc-okhttp is vulnerable to Improper Certificate Validation in versions 0.7.0 - 1.68.2 and 1.69.0 - 1.69.0.

How to fix this

Upgrade the io.grpc:grpc-okhttp library to the patch version.