Man-in-the-Middle (MitM) attack in OkHttp - CVE-2016-2402
Published: July 21, 2022
Vulnerability identifier: #VU65650
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2402
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to an unspecified error. A remote attacker can send a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate to bypass certificate pinning.
Affected software
OkHttp
IBM PureData System for Operational Analytics
Fedora
okio
okhttp
Cloud Pak for Security (CP4S)
IBM PureData System for Operational Analytics
Fedora
okio
okhttp
Cloud Pak for Security (CP4S)
How to mitigate CVE-2016-2402
Install updates from vendor's website.
OkHttp - addressed in versions 2.7.4, 3.1.2
okio - update to 1.6.0-1.fc23
Cloud Pak for Security (CP4S) - update to 1.10.14.0
okhttp - update to 2.7.4-1.fc23
okio - update to 1.6.0-1.fc23
Cloud Pak for Security (CP4S) - update to 1.10.14.0
okhttp - update to 2.7.4-1.fc23
External References
- http://www.openwall.com/lists/oss-security/2016/02/10/8
- http://www.openwall.com/lists/oss-security/2016/02/18/7
- https://koz.io/pinning-cve-2016-2402/
- https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E
- https://publicobject.com/2016/02/11/okhttp-certificate-pinning-vulnerability/