CVE-2020-11050

CRITICAL

Java-WebSocket <=1.4.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.

References (1)

Core 1
Core References

Scores

CVSS v3 9.0
EPSS 0.0077
EPSS Percentile 50.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-295 CWE-297
Status published
Products (2)
java-websocket_project/java-websocket < 1.4.1
org.java-websocket/Java-WebSocket 0 - 1.5.0Maven
Published May 07, 2020
Tracked Since Feb 18, 2026