CVE-2021-0341
published 2021-02-10CVE-2021-0341: In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.88%
55.5th percentile
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | external_okhttp | >= 10:0 < 10:2021-02-01 | 10:2021-02-01 |
| platform | external_okhttp | >= 11:0 < 11:2021-02-01 | 11:2021-02-01 |
| platform | external_okhttp | >= 8.0:0 < 8.0:2021-02-01 | 8.0:2021-02-01 |
| platform | external_okhttp | >= 8.1:0 < 8.1:2021-02-01 | 8.1:2021-02-01 |
| platform | external_okhttp | >= 9:0 < 9:2021-02-01 | 9:2021-02-01 |
| platform | libcore | >= 10:0 < 10:2021-02-01 | 10:2021-02-01 |
| platform | libcore | >= 11:0 < 11:2021-02-01 | 11:2021-02-01 |
| platform | libcore | >= 8.0:0 < 8.0:2021-02-01 | 8.0:2021-02-01 |
| platform | libcore | >= 8.1:0 < 8.1:2021-02-01 | 8.1:2021-02-01 |
| platform | libcore | >= 9:0 < 9:2021-02-01 | 9:2021-02-01 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Square OkHttp can accept the wrong certificate
osv·2022-05-24
CVE-2021-0341 [HIGH] Square OkHttp can accept the wrong certificate
Square OkHttp can accept the wrong certificate
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android ID: A-171980069
GHSA
Square OkHttp can accept the wrong certificate
ghsa·2022-05-24
CVE-2021-0341 [HIGH] CWE-295 Square OkHttp can accept the wrong certificate
Square OkHttp can accept the wrong certificate
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android ID: A-171980069
OSV
CVE-2021-0341: In verifyHostName of OkHostnameVerifier
osv·2021-02-01
CVE-2021-0341 CVE-2021-0341: In verifyHostName of OkHostnameVerifier
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CISA ICS
Siemens SIMATIC
cisa_ics·2024-03-14
Siemens SIMATIC
ICS Advisory
##
Siemens SIMATIC
Release DateMarch 14, 2024
Alert CodeICSA-24-074-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC
- Vulnerabilities: Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Missing Encryption of Sensitive Data, Incorrect Permission Assignment for Critical Resource, Expected Beha
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (OkHttp) — CVE-2021-0341
vendor_oracle·2024-01-15·CVSS 7.5
CVE-2021-0341 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (OkHttp) — CVE-2021-0341
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (OkHttp) vulnerability
CVE: CVE-2021-0341
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Red Hat
okhttp: information disclosure via improperly used cryptographic function
vendor_redhat·2021-02-10·CVSS 7.5
CVE-2021-0341 [HIGH] CWE-295 okhttp: information disclosure via improperly used cryptographic function
okhttp: information disclosure via improperly used cryptographic function
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: okhttp (Red Hat AMQ Broker 7) - Not affected
Package: okhttp (Red Hat build of Apicurio Registry 2) - Not affected
Package: okhttp (Red Hat build of Quarkus) - Not affected
Package: okhttp (Red Hat Decision Manager 7) - Ou
Android
CVE-2021-0341: Android Security Bulletin 2021-02-01
CVE: CVE-2021-0341
Severity: HIGH
Type: ID
Affected AOSP versions: 8
vendor_android·2021-02-01·CVSS 7.5
CVE-2021-0341 [HIGH] CVE-2021-0341: Android Security Bulletin 2021-02-01
CVE: CVE-2021-0341
Severity: HIGH
Type: ID
Affected AOSP versions: 8
Android Security Bulletin 2021-02-01
CVE: CVE-2021-0341
Severity: HIGH
Type: ID
Affected AOSP versions: 8.1, 9, 10, 11
References: A-171980069
[2]
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-02-10
Published