[ 
https://issues.apache.org/jira/browse/CXF-8437?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17304328#comment-17304328
 ] 

Alan Mehio commented on CXF-8437:
---------------------------------

[~ffang] Many thanks for your quick answer. Yes true me PR is not against the  
latest. The example which is given in the codeQL (example two) is the same as 
the one which I have but the one from the 3.4.x does not throw RuntimeException 
 but rather return false in catch statement .

I will update my PR to the 3.4.x as suggested and see if I get the same issue. 

 

 

 

 

> DefaultHostnameVerifier   accepts any certificate as valid which is a secure 
> issue
> ----------------------------------------------------------------------------------
>
>                 Key: CXF-8437
>                 URL: https://issues.apache.org/jira/browse/CXF-8437
>             Project: CXF
>          Issue Type: Improvement
>    Affects Versions: 3.4.2
>            Reporter: Alan Mehio
>            Assignee: Freeman Yue Fang
>            Priority: Minor
>
> The GitHub code scanning  is  flagging an error[ 
> see|[https://github.com/apache/cxf/pull/755/checks?check_run_id=2125425364]]
>  for this security issue  [unsafe hostname 
> verification|https://codeql.github.com/codeql-query-help/java/java-unsafe-hostname-verification/]
> from CodeQL documenation.  
> Any idea if the Github new annotation on unchanged files is helping or it is 
> disturbing  
>   



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to