...
[redacted for readability]
...
{
"isVirtual": false,
"fileName": "okhttp-4.8.0.jar",
"filePath": "\/Users\/sushi2k\/.gradle\/caches\/modules-2\/files-2.1\/com.squareup.okhttp3\/okhttp\/4.8.0\/5c34a8c35bb3fd5ec39d3a67ceae691d0f3eb455\/okhttp-4.8.0.jar",
"md5": "5132d18a9ed0b5eb9a6137885959bcb5",
"sha1": "5c34a8c35bb3fd5ec39d3a67ceae691d0f3eb455",
"sha256": "04d68254c5216d059504d97e2cf2f8ba7922453059701a5adc65652809dd1599",
...
[redacted for readability]
...
"packages": [
{
"id": "pkg:maven\/com.squareup.okhttp3\/[email protected]",
"confidence": "HIGHEST",
"url": "https:\/\/ossindex.sonatype.org\/component\/pkg:maven\/com.squareup.okhttp3\/[email protected]?utm_source=dependency-check&utm_medium=integration&utm_content=10.0.4"
}
],
"vulnerabilityIds": [
{
"id": "cpe:2.3:a:squareup:okhttp:4.8.0:*:*:*:*:*:*:*",
"confidence": "LOW"
},
{
"id": "cpe:2.3:a:squareup:okhttp3:4.8.0:*:*:*:*:*:*:*",
"confidence": "LOW"
}
],
"vulnerabilities": [
{
"source": "OSSINDEX",
"name": "CVE-2021-0341",
"severity": "HIGH",
"cvssv3": {
"baseScore": 7.5,
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseSeverity": "HIGH",
"version": "3.1"
},
"cwes": [
"CWE-295"
],
"description": "In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069",
"notes": "",
"references": [
{
"source": "OSSINDEX",
"url": "https:\/\/ossindex.sonatype.org\/vulnerability\/CVE-2021-0341?component-type=maven&component-name=com.squareup.okhttp3%2Fokhttp&utm_source=dependency-check&utm_medium=integration&utm_content=10.0.4",
"name": "[CVE-2021-0341] CWE-295: Improper Certificate Validation"
},
{
"source": "OSSIndex",
"url": "https:\/\/source.android.com\/security\/bulletin\/2021-02-01#android-runtime",
"name": "https:\/\/source.android.com\/security\/bulletin\/2021-02-01#android-runtime"
},
{
"source": "OSSIndex",
"url": "http:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2021-0341",
"name": "http:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2021-0341"
},
{
"source": "OSSIndex",
"url": "https:\/\/github.com\/square\/okhttp\/pull\/6353",
"name": "https:\/\/github.com\/square\/okhttp\/pull\/6353"
}
],
"vulnerableSoftware": [
{
"software": {
"id": "cpe:2.3:a:com.squareup.okhttp3:okhttp:4.8.0:*:*:*:*:*:*:*",
"vulnerabilityIdMatched": "true"
}
}
]
},
...
[redacted for readability]
...