{"id":"GHSA-4hxv-95rc-jqg7","summary":"nv-websocket-client allows attackers to spoof SSL/TLS servers via an arbitrary valid certificate","details":"The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate.","aliases":["CVE-2017-1000209"],"modified":"2023-11-08T03:58:44.169282Z","published":"2022-05-17T00:18:13Z","database_specific":{"github_reviewed_at":"2022-11-08T12:38:22Z","nvd_published_at":"2017-11-17T02:29:00Z","cwe_ids":["CWE-295"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000209"},{"type":"WEB","url":"https://github.com/TakahikoKawasaki/nv-websocket-client/pull/107"}],"affected":[{"package":{"name":"com.neovisionaries:nv-websocket-client","ecosystem":"Maven","purl":"pkg:maven/com.neovisionaries/nv-websocket-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1"}]}],"versions":["1.0","1.1","1.10","1.11","1.12","1.13","1.14","1.15","1.16","1.17","1.18","1.19","1.2","1.20","1.21","1.22","1.23","1.24","1.25","1.26","1.27","1.28","1.29","1.3","1.30","1.31","1.4","1.5","1.6","1.7","1.8","1.9","2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4hxv-95rc-jqg7/GHSA-4hxv-95rc-jqg7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}