Description
The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate.
Remediation
References
https://github.com/TakahikoKawasaki/nv-websocket-client/pull/107
Related Vulnerabilities
CVE-2021-35513 Vulnerability in maven package org.webjars.npm:mermaid
CVE-2020-28482 Vulnerability in npm package fastify-csrf
CVE-2020-6541 Vulnerability in npm package electron
CVE-2014-3681 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2017-17068 Vulnerability in maven package org.webjars.npm:auth0-js