Description
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
Remediation
References
https://apidoc.gitee.com/dromara/hutool/cn/hutool/http/ssl/DefaultSSLInfo.html
https://github.com/dromara/hutool/issues/2042
Related Vulnerabilities
CVE-2018-5382 Vulnerability in maven package org.bouncycastle:bcprov-jdk16
CVE-2021-23445 Vulnerability in npm package datatables.net
CVE-2021-23771 Vulnerability in npm package notevil
CVE-2022-25296 Vulnerability in npm package bodymen
CVE-2022-38749 Vulnerability in maven package org.yaml:snakeyaml