Oval Definition:oval:com.ubuntu.bionic:def:201820200000
Revision Date:2019-04-18Version:1
Title:CVE-2018-20200 on Ubuntu 18.04 LTS (bionic) - medium.
Description:** DISPUTED ** CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application. NOTE: This id is disputed because some parties don't consider this is a vulnerability. Their rationale can be found in https://github.com/square/okhttp/issues/4967.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-20200
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND The vulnerability of the 'libokhttp-java' package in bionic is not known (status: 'needs-triage'). It is pending evaluation.
  • BACK