{"id":"GHSA-gw55-jm4h-x339","summary":"Improper Validation of Certificate with Host Mismatch in Java-WebSocket","details":"The Java-WebSocket Client does not perform hostname verification.\n\n - This means that SSL certificates of other hosts are accepted as long as they are trusted. To exploit this vulnerability an attacker has to perform a man-in-the-middle (MITM) attack between a Java application using the Java-WebSocket Client and an WebSocket server it's connecting to.\n - TLS normally protects users and systems against MITM attacks, it cannot if certificates from other trusted hosts are accepted by the client.\n\nFor more information see: CWE-297: Improper Validation of Certificate with Host Mismatch - https://cwe.mitre.org/data/definitions/297.html\n\n## Important note\n\nThe OWASP Dependency-Check (https://jeremylong.github.io/DependencyCheck/index.html) may report that a dependency of your project is affected by this security vulnerability, but you don't use this lib.\nThis is caused by the fuzzy search in the OWASP implementation.\nCheck out this issue (https://github.com/TooTallNate/Java-WebSocket/issues/1019#issuecomment-628507934) for more information and a way to suppress the warning.","aliases":["CVE-2020-11050"],"modified":"2026-09-10T03:48:47.350626091Z","published":"2020-05-08T18:54:39Z","database_specific":{"cwe_ids":["CWE-295","CWE-297"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-05-08T18:54:10Z","nvd_published_at":"2020-05-07T21:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/TooTallNate/Java-WebSocket/security/advisories/GHSA-gw55-jm4h-x339"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-11050"},{"type":"PACKAGE","url":"https://github.com/TooTallNate/Java-WebSocket"}],"affected":[{"package":{"name":"org.java-websocket:Java-WebSocket","ecosystem":"Maven","purl":"pkg:maven/org.java-websocket/Java-WebSocket"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.0"}]}],"versions":["1.3.0","1.3.4","1.3.5","1.3.6","1.3.7","1.3.8","1.3.9","1.4.0","1.4.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.4.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-gw55-jm4h-x339/GHSA-gw55-jm4h-x339.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}