grpc-okhttp is vulnerable to Improper Certificate Validation
75
High Risk
Affected versions of this package fail to properly validate security certificates. In the verifyHostName method of OkHostnameVerifier.java, a flaw in cryptographic implementation may allow acceptance of certificates for incorrect domains when using non-ASCII subjects. This vulnerability can lead to remote information disclosure without requiring user interaction or additional execution privileges.
You are affected if you are using a version that falls within the vulnerable range.
grpc-okhttp is vulnerable to Improper Certificate Validation in versions 0.7.0 - 1.68.2 and 1.69.0 - 1.69.0.
Upgrade the io.grpc:grpc-okhttp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant