WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false).
References
Link | Resource |
---|---|
http://seclists.org/bugtraq/2017/Apr/66 | |
https://github.com/daltoniam/Starscream/commit/dbeb1190b8dcbff4f0b797f9e9d9b9b864d1f0d6 | Patch Third Party Advisory |
https://github.com/daltoniam/Starscream/releases/tag/2.0.4 | Release Notes Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2017-04-06T14:00:00
Updated: 2017-04-24T16:57:01
Reserved: 2017-03-20T00:00:00
Link: CVE-2017-7192
JSON object: View
NVD Information
Status : Modified
Published: 2017-04-06T14:59:00.363
Modified: 2017-04-25T01:59:01.170
Link: CVE-2017-7192
JSON object: View
Redhat Information
No data.
CWE