{"api_version":"1","generated_at":"2026-07-23T12:31:17+00:00","cve":"CVE-2020-11050","urls":{"html":"https://cve.report/CVE-2020-11050","api":"https://cve.report/api/cve/CVE-2020-11050.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-11050","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-11050"},"summary":{"title":"CVE-2020-11050","description":"In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2020-05-07 21:15:00","updated_at":"2021-10-07 17:19:00"},"problem_types":["CWE-295"],"metrics":[],"references":[{"url":"https://github.com/TooTallNate/Java-WebSocket/security/advisories/GHSA-gw55-jm4h-x339","name":"https://github.com/TooTallNate/Java-WebSocket/security/advisories/GHSA-gw55-jm4h-x339","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"`WebSocketClient` does not perform SSL hostname validation · Advisory · TooTallNate/Java-WebSocket · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-11050","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-11050","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"11050","vulnerable":"1","versionEndIncluding":"1.4.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"java-websocket_project","cpe5":"java-websocket","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-11050","qid":"980488","title":"Java (maven) Security Update for org.java-websocket:Java-WebSocket (GHSA-gw55-jm4h-x339)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2020-11050","STATE":"PUBLIC","TITLE":"Improper Validation of Certificate with Host Mismatch in Java-WebSocket"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Java-WebSocket","version":{"version_data":[{"version_value":"<= 1.4.1"}]}}]},"vendor_name":"TooTallNate"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-297: Improper Validation of Certificate with Host Mismatch"}]}]},"references":{"reference_data":[{"name":"https://github.com/TooTallNate/Java-WebSocket/security/advisories/GHSA-gw55-jm4h-x339","refsource":"CONFIRM","url":"https://github.com/TooTallNate/Java-WebSocket/security/advisories/GHSA-gw55-jm4h-x339"}]},"source":{"advisory":"GHSA-gw55-jm4h-x339","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2020-05-07 21:15:00","lastModifiedDate":"2021-10-07 17:19:00","problem_types":["CWE-295"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:java-websocket_project:java-websocket:*:*:*:*:*:*:*:*","versionEndIncluding":"1.4.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"11050","Ordinal":"171595","Title":"CVE-2020-11050","CVE":"CVE-2020-11050","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"11050","Ordinal":"1","NoteData":"In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"11050","Ordinal":"2","NoteData":"2020-05-07","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"11050","Ordinal":"3","NoteData":"2020-05-07","Type":"Other","Title":"Modified"}]}}}