CVE-2021-0341: High severity Google Android vulnerability
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.1 Android-9 Android-10 Android-11 Android ID: A-171980069
https://android.googlesource.com/platform/external/okhttp/+/ddc934efe3ed06ce34f3724d41cfbdcd7e7358fc%5E%21/#F1
Other sources
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.7-1.redhat_00001.1.el7 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.7-1.redhat_00001.1.el8 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.7-1.redhat_00001.1.el9 - Upgrade
Upgrade
redhat/Android_ID Ato a version that resolves this vulnerability.Fixed in 171980069
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-0341?
The severity of CVE-2021-0341 is considered to be high due to potential remote information disclosure.
How do I fix CVE-2021-0341?
To fix CVE-2021-0341, ensure you update your software to the latest version that addresses this vulnerability.
What software is affected by CVE-2021-0341?
CVE-2021-0341 affects various versions of the rh-sso7-keycloak package across Red Hat Enterprise Linux 7, 8, and 9, as well as specific Android versions.
Is user interaction required for the exploitation of CVE-2021-0341?
No, user interaction is not needed for the exploitation of CVE-2021-0341.
What is the impact of CVE-2021-0341 on applications?
CVE-2021-0341 could lead to remote information disclosure, allowing attackers to manipulate certificate validation for incorrect domains.