Description
The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate.
Remediation
References
https://github.com/TakahikoKawasaki/nv-websocket-client/pull/107
Related Vulnerabilities
CVE-2020-5529 Vulnerability in maven package net.sourceforge.htmlunit:htmlunit
CVE-2022-36437 Vulnerability in maven package com.hazelcast:hazelcast-enterprise
CVE-2019-12402 Vulnerability in maven package org.apache.commons:commons-compress
CVE-2020-1951 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2022-38749 Vulnerability in maven package org.yaml:snakeyaml