Alan Mehio created CXF-8437:
-------------------------------
Summary: DefaultHostnameVerifier ccepts any certificate as valid
which is a secure issue
Key: CXF-8437
URL: https://issues.apache.org/jira/browse/CXF-8437
Project: CXF
Issue Type: Improvement
Affects Versions: 3.4.2
Reporter: Alan Mehio
The GitHub code scanning is flagging an error[
see|[https://github.com/apache/cxf/pull/755/checks?check_run_id=2125425364]]
for this security issue [unsafe hostname
verification|https://codeql.github.com/codeql-query-help/java/java-unsafe-hostname-verification/]
from CodeQL documenation.
Any idea if the Github new annotation on unchanged files is helping or it is
disturbing
--
This message was sent by Atlassian Jira
(v8.3.4#803005)