First published: Wed Feb 16 2022(Updated: )
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hutool Hutool | =5.7.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22885 is a vulnerability in Hutool v5.7.18 that allows the HttpRequest class to ignore all TLS/SSL certificate validation.
CVE-2022-22885 has a severity rating of 9.8 (Critical).
Hutool v5.7.18 is affected by CVE-2022-22885.
To fix CVE-2022-22885, update Hutool to a version that does not have this vulnerability.
You can find more information about CVE-2022-22885 at the following references: [Reference 1](https://apidoc.gitee.com/dromara/hutool/cn/hutool/http/ssl/DefaultSSLInfo.html), [Reference 2](https://github.com/dromara/hutool/issues/2042).