CVE-2022-22885: Critical severity hutool vulnerability
Published Feb 16, 2022
·Updated
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
Affected Software
1 affected component
Hutool Hutool=5.7.18
Event History
Feb 16, 2022
CVE Published
via MITRE·09:56 PM
Data Sourced
via MITRE·09:56 PM
Description
Frequently Asked Questions
1
What is CVE-2022-22885?
CVE-2022-22885 is a vulnerability in Hutool v5.7.18 that allows the HttpRequest class to ignore all TLS/SSL certificate validation.
2
How serious is CVE-2022-22885?
CVE-2022-22885 has a severity rating of 9.8 (Critical).
3
Which version of Hutool is affected by CVE-2022-22885?
Hutool v5.7.18 is affected by CVE-2022-22885.
4
How can I fix CVE-2022-22885?
To fix CVE-2022-22885, update Hutool to a version that does not have this vulnerability.
5
Where can I find more information about CVE-2022-22885?
You can find more information about CVE-2022-22885 at the following references: [Reference 1](https://apidoc.gitee.com/dromara/hutool/cn/hutool/http/ssl/DefaultSSLInfo.html), [Reference 2](https://github.com/dromara/hutool/issues/2042).