Description
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
Remediation
References
https://apidoc.gitee.com/dromara/hutool/cn/hutool/http/ssl/DefaultSSLInfo.html
https://github.com/dromara/hutool/issues/2042
Related Vulnerabilities
CVE-2019-1010091 Vulnerability in npm package tinymce
CVE-2020-15156 Vulnerability in npm package nodebb-plugin-blog-comments
CVE-2017-12629 Vulnerability in maven package org.apache.lucene:lucene-queryparser
CVE-2018-1320 Vulnerability in maven package org.apache.thrift:libthrift
CVE-2023-46497 Vulnerability in npm package @evershop/evershop