Bug 2154086 (CVE-2021-0341)

Summary: CVE-2021-0341 okhttp: information disclosure via improperly used cryptographic function
Product: [Other] Security Response Reporter: Chess Hazlett <chazlett>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aileenc, alazarot, anstephe, asoldano, ataylor, avibelli, balejosg, bbaranow, bgeorges, bmaxwell, boliveir, brian.stansberry, cdewolf, chazlett, clement.escoffier, dandread, darran.lofthouse, dfreiber, dkreling, dosoudil, emingora, eric.wittmann, fjuma, fmongiar, gjospin, gmalinko, gsmet, hamadhan, ibek, ivassile, iweiss, janstey, jburrell, jcantril, jnethert, jpavlik, jrokos, jross, jscholz, jstastny, jwon, kverlaen, lgao, lthon, max.andersen, mizdebsk, mnovotny, mokumar, mosmerov, msochure, msvehla, nboldt, nwallace, pantinor, pdelbell, pdrozd, peholase, periklis, pgallagh, pjindal, pmackay, probinso, pskopek, rguimara, rkieley, rogbas, rrajasek, rruss, rstancel, rsvoboda, sbiarozk, scorneli, sdouglas, smaestri, sthorger, swoodman, tom.jenkinson, vkumar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Android_ID A-171980069 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-02-16 01:11:55 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2159795, 2159797, 2159798    
Bug Blocks: 2154088    

Description Chess Hazlett 2022-12-15 19:56:59 UTC
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.1 Android-9 Android-10 Android-11 Android ID: A-171980069

https://android.googlesource.com/platform/external/okhttp/+/ddc934efe3ed06ce34f3724d41cfbdcd7e7358fc%5E%21/#F1

Comment 3 Chess Hazlett 2023-01-10 18:33:36 UTC
Created log4j tracking bugs for this issue:

Affects: fedora-all [bug 2159795]

Comment 6 errata-xmlrpc 2023-02-14 11:49:09 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2023:0756 https://access.redhat.com/errata/RHSA-2023:0756

Comment 7 Product Security DevOps Team 2023-02-16 01:11:51 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-0341

Comment 9 errata-xmlrpc 2023-05-10 11:22:38 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.6 for RHEL 8

Via RHSA-2023:2706 https://access.redhat.com/errata/RHSA-2023:2706

Comment 10 errata-xmlrpc 2023-05-10 11:23:13 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.6 for RHEL 9

Via RHSA-2023:2707 https://access.redhat.com/errata/RHSA-2023:2707

Comment 11 errata-xmlrpc 2023-05-10 11:23:41 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.6 for RHEL 7

Via RHSA-2023:2705 https://access.redhat.com/errata/RHSA-2023:2705

Comment 12 errata-xmlrpc 2023-05-10 11:59:46 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On

Via RHSA-2023:2713 https://access.redhat.com/errata/RHSA-2023:2713

Comment 13 errata-xmlrpc 2023-05-10 13:41:54 UTC
This issue has been addressed in the following products:

  Red Hat Data Grid 8.4.2

Via RHSA-2023:2723 https://access.redhat.com/errata/RHSA-2023:2723

Comment 14 errata-xmlrpc 2023-05-10 14:33:02 UTC
This issue has been addressed in the following products:

  RHEL-8 based Middleware Containers

Via RHSA-2023:2710 https://access.redhat.com/errata/RHSA-2023:2710

Comment 15 errata-xmlrpc 2023-05-18 09:54:33 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Streams 2.4.0

Via RHSA-2023:3223 https://access.redhat.com/errata/RHSA-2023:3223