Skip to content

Conversation

@ejona86
Copy link
Member

@ejona86 ejona86 commented Jan 15, 2025

Implement fix to address a security issue related to maliciously crafted hostnames during certificate validation in OkHttp

grpc-java is susceptible to CVE-2021-0341

This mirrors the okhttp patch for this exploit available in square/okhttp#6353

Backport of #11749

* Validate that hostname is ascii in OkHostnameVerifier.java
@ejona86 ejona86 requested a review from larry-safran January 15, 2025 22:02
@ejona86 ejona86 merged commit eb14478 into grpc:v1.68.x Jan 15, 2025
15 checks passed
@ejona86 ejona86 deleted the backport-okhttp-host-1.68 branch January 15, 2025 22:55
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Apr 16, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants