Description
The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate.
Remediation
References
https://github.com/TakahikoKawasaki/nv-websocket-client/pull/107
Related Vulnerabilities
CVE-2020-35214 Vulnerability in maven package io.atomix:atomix
CVE-2021-41184 Vulnerability in npm package jquery-ui
CVE-2017-2606 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2015-7559 Vulnerability in maven package org.apache.activemq:activemq-core
CVE-2021-21347 Vulnerability in maven package com.thoughtworks.xstream:xstream