Description
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
Remediation
References
https://apidoc.gitee.com/dromara/hutool/cn/hutool/http/ssl/DefaultSSLInfo.html
https://github.com/dromara/hutool/issues/2042
Related Vulnerabilities
CVE-2018-1000118 Vulnerability in npm package electron
CVE-2022-31777 Vulnerability in maven package org.apache.spark:spark-core_2.13
CVE-2020-2119 Vulnerability in maven package org.jenkins-ci.plugins:azure-ad
CVE-2022-36900 Vulnerability in maven package com.compuware.jenkins:compuware-zadviser-api
CVE-2019-11272 Vulnerability in maven package org.springframework.security:spring-security-core