Bug 2154086 (CVE-2021-0341) - CVE-2021-0341 okhttp: information disclosure via improperly used cryptographic function
Summary: CVE-2021-0341 okhttp: information disclosure via improperly used cryptographi...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2021-0341
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2159795 2159797 2159798
Blocks: 2154088
TreeView+ depends on / blocked
 
Reported: 2022-12-15 19:56 UTC by Chess Hazlett
Modified: 2023-05-24 04:05 UTC (History)
78 users (show)

Fixed In Version: Android_ID A-171980069
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2023-02-16 01:11:55 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:0756 0 None None None 2023-02-14 11:49:12 UTC
Red Hat Product Errata RHSA-2023:2705 0 None None None 2023-05-10 11:23:44 UTC
Red Hat Product Errata RHSA-2023:2706 0 None None None 2023-05-10 11:22:42 UTC
Red Hat Product Errata RHSA-2023:2707 0 None None None 2023-05-10 11:23:16 UTC
Red Hat Product Errata RHSA-2023:2710 0 None None None 2023-05-10 14:33:07 UTC
Red Hat Product Errata RHSA-2023:2713 0 None None None 2023-05-10 11:59:49 UTC
Red Hat Product Errata RHSA-2023:2723 0 None None None 2023-05-10 13:41:58 UTC
Red Hat Product Errata RHSA-2023:3223 0 None None None 2023-05-18 09:54:36 UTC

Description Chess Hazlett 2022-12-15 19:56:59 UTC
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.1 Android-9 Android-10 Android-11 Android ID: A-171980069

https://android.googlesource.com/platform/external/okhttp/+/ddc934efe3ed06ce34f3724d41cfbdcd7e7358fc%5E%21/#F1

Comment 3 Chess Hazlett 2023-01-10 18:33:36 UTC
Created log4j tracking bugs for this issue:

Affects: fedora-all [bug 2159795]

Comment 6 errata-xmlrpc 2023-02-14 11:49:09 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2023:0756 https://access.redhat.com/errata/RHSA-2023:0756

Comment 7 Product Security DevOps Team 2023-02-16 01:11:51 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-0341

Comment 9 errata-xmlrpc 2023-05-10 11:22:38 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.6 for RHEL 8

Via RHSA-2023:2706 https://access.redhat.com/errata/RHSA-2023:2706

Comment 10 errata-xmlrpc 2023-05-10 11:23:13 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.6 for RHEL 9

Via RHSA-2023:2707 https://access.redhat.com/errata/RHSA-2023:2707

Comment 11 errata-xmlrpc 2023-05-10 11:23:41 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.6 for RHEL 7

Via RHSA-2023:2705 https://access.redhat.com/errata/RHSA-2023:2705

Comment 12 errata-xmlrpc 2023-05-10 11:59:46 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On

Via RHSA-2023:2713 https://access.redhat.com/errata/RHSA-2023:2713

Comment 13 errata-xmlrpc 2023-05-10 13:41:54 UTC
This issue has been addressed in the following products:

  Red Hat Data Grid 8.4.2

Via RHSA-2023:2723 https://access.redhat.com/errata/RHSA-2023:2723

Comment 14 errata-xmlrpc 2023-05-10 14:33:02 UTC
This issue has been addressed in the following products:

  RHEL-8 based Middleware Containers

Via RHSA-2023:2710 https://access.redhat.com/errata/RHSA-2023:2710

Comment 15 errata-xmlrpc 2023-05-18 09:54:33 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Streams 2.4.0

Via RHSA-2023:3223 https://access.redhat.com/errata/RHSA-2023:3223


Note You need to log in before you can comment on or make changes to this bug.