OkHttp Certificate Pinning Vulnerability CVE-2016-2402

This issue belongs to an archived project. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • 1
    • Severity 3 - Minor
    • 6

      Issue Summary

      Portfolio uses Okhttp 2.2.0 which has an identified vulnerability:

      https://nvd.nist.gov/vuln/detail/CVE-2016-2402
      https://www.securityfocus.com/bid/83296/info
      https://publicobject.com/2016/02/11/okhttp-certificate-pinning-vulnerability/

      Steps to Reproduce

      https://koz.io/pinning-cve-2016-2402/

      Expected Results

      -

      Actual Results

      -

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available

              Assignee:
              Chris Francuz
              Reporter:
              Rene C. [Atlassian Support] (Inactive)
              Archiver:
              Aakrity Tibrewal

                Created:
                Updated:
                Resolved:
                Archived: