Man-in-the-Middle (MitM) attack in OkHttp - CVE-2016-2402

 

Man-in-the-Middle (MitM) attack in OkHttp - CVE-2016-2402

Published: July 21, 2022


Vulnerability identifier: #VU65650
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2402
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to an unspecified error. A remote attacker can send a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate to bypass certificate pinning.


Affected software

OkHttp
IBM PureData System for Operational Analytics
Fedora
okio
okhttp
Cloud Pak for Security (CP4S)

How to mitigate CVE-2016-2402

Install updates from vendor's website.

OkHttp - addressed in versions 2.7.4, 3.1.2
okio - update to 1.6.0-1.fc23
Cloud Pak for Security (CP4S) - update to 1.10.14.0
okhttp - update to 2.7.4-1.fc23

External References

Related Security Bulletins