Description
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
Remediation
References
https://apidoc.gitee.com/dromara/hutool/cn/hutool/http/ssl/DefaultSSLInfo.html
https://github.com/dromara/hutool/issues/2042
Related Vulnerabilities
CVE-2020-8116 Vulnerability in maven package org.webjars.npm:dot-prop
CVE-2020-13955 Vulnerability in maven package org.apache.calcite:calcite-core
CVE-2021-39236 Vulnerability in maven package org.apache.ozone:ozone-main
CVE-2023-29234 Vulnerability in maven package org.apache.dubbo:dubbo
CVE-2023-38905 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core