Description
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
Remediation
References
https://apidoc.gitee.com/dromara/hutool/cn/hutool/http/ssl/DefaultSSLInfo.html
https://github.com/dromara/hutool/issues/2042
Related Vulnerabilities
CVE-2021-40865 Vulnerability in maven package org.apache.storm:storm-server
CVE-2023-25761 Vulnerability in maven package org.jenkins-ci.plugins:junit
CVE-2019-20149 Vulnerability in maven package org.webjars.bowergithub.jonschlinkert:kind-of
CVE-2020-2113 Vulnerability in maven package org.jenkins-ci.tools:git-parameter
CVE-2022-36889 Vulnerability in maven package org.jenkins-ci.plugins:deployer-framework