Description
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
Remediation
References
https://apidoc.gitee.com/dromara/hutool/cn/hutool/http/ssl/DefaultSSLInfo.html
https://github.com/dromara/hutool/issues/2042
Related Vulnerabilities
CVE-2022-0272 Vulnerability in maven package io.gitlab.arturbosch.detekt:detekt-core
CVE-2020-8125 Vulnerability in npm package klona
CVE-2022-24822 Vulnerability in npm package @podium/layout
CVE-2019-1003080 Vulnerability in maven package org.jenkins-ci.plugins:openshift-deployer
CVE-2017-5664 Vulnerability in maven package org.apache.tomcat:tomcat-catalina