mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
30 lines
1.3 KiB
Markdown
30 lines
1.3 KiB
Markdown
![]() |
### [CVE-2018-20200](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20200)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
** DISPUTED ** CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application. NOTE: This id is disputed because some parties don't consider this is a vulnerability. Their rationale can be found in https://github.com/square/okhttp/issues/4967.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://cxsecurity.com/issue/WLB-2018120252
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/dotanuki-labs/android-oss-cves-research
|
||
|
- https://github.com/hinat0y/Dataset1
|
||
|
- https://github.com/hinat0y/Dataset10
|
||
|
- https://github.com/hinat0y/Dataset11
|
||
|
- https://github.com/hinat0y/Dataset12
|
||
|
- https://github.com/hinat0y/Dataset2
|
||
|
- https://github.com/hinat0y/Dataset3
|
||
|
- https://github.com/hinat0y/Dataset4
|
||
|
- https://github.com/hinat0y/Dataset5
|
||
|
- https://github.com/hinat0y/Dataset6
|
||
|
- https://github.com/hinat0y/Dataset7
|
||
|
- https://github.com/hinat0y/Dataset8
|
||
|
- https://github.com/hinat0y/Dataset9
|
||
|
|