Description
The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate.
Remediation
References
https://github.com/TakahikoKawasaki/nv-websocket-client/pull/107
Related Vulnerabilities
CVE-2020-28452 Vulnerability in maven package com.softwaremill.akka-http-session:core_2.11
CVE-2019-18797 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2020-2276 Vulnerability in maven package org.jenkins-ci.plugins:selection-tasks-plugin
CVE-2021-26539 Vulnerability in maven package org.webjars.npm:sanitize-html
CVE-2020-6463 Vulnerability in maven package org.webjars.npm:electron