netty-handler-ssl-ocsp is vulnerable to Improper Certificate Validation
74
High Risk
Netty's OcspClient verifies OCSP response signatures but never checks that the response's CertificateID matches the certificate under validation. An attacker who can intercept or proxy OCSP traffic can replay a legitimately signed GOOD response that was issued for any other non-revoked certificate from the same CA, and the client will accept it for a revoked or unrelated target certificate. This breaks RFC 6960 revocation checking and allows certificate validation bypass.
You are affected if you are using a version that falls within the vulnerable range and your application uses Netty's OcspClient to check certificate revocation status over OCSP.
netty-handler-ssl-ocsp is vulnerable to Improper Certificate Validation in versions 4.1.86.Final - 4.1.135.Final and 4.2.0.Final - 4.2.15.Final.
Upgrade the io.netty:netty-handler-ssl-ocsp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant