Intel

AIKIDO-2025-10029

grpc-okhttp is vulnerable to Improper Certificate Validation

Improper Certificate ValidationCVE-2021-0341 Published Jan 20, 2025

75

High Risk

This Affects:

JAVAgrpc-okhttp
0.7.0 - 1.68.2
Fixed in 1.68.3
1.69.0 - 1.69.0
Fixed in 1.69.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package fail to properly validate security certificates. In the verifyHostName method of OkHostnameVerifier.java, a flaw in cryptographic implementation may allow acceptance of certificates for incorrect domains when using non-ASCII subjects. This vulnerability can lead to remote information disclosure without requiring user interaction or additional execution privileges.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

grpc-okhttp is vulnerable to Improper Certificate Validation in versions 0.7.0 - 1.68.2 and 1.69.0 - 1.69.0.

How to fix this

Upgrade the io.grpc:grpc-okhttp library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform