okhttp: certificate pinning bypass
Published Apr 18, 2019
5.9
MEDIUMCVSS 3.0
EPSS 2.48%
Description
CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application. NOTE: This id is disputed because some parties don't consider this is a vulnerability. Their rationale can be found in https://github.com/square/okhttp/issues/4967
Affected products
No data.
No data.
Red Hat Decision Manager 7
okhttp
Not affected
Red Hat Fuse 7
okhttp
Not affected
Red Hat OpenShift Application Runtimes
okhttp
Not affected
Red Hat OpenShift Container Platform 3.10
elasticsearch-cloud-kubernetes
Not affected
Red Hat OpenShift Container Platform 3.10
openshift-elasticsearch-plugin
Not affected
Red Hat OpenShift Container Platform 3.11
openshift3/ose-logging-elasticsearch5
Not affected
Red Hat OpenShift Container Platform 3.9
elasticsearch-cloud-kubernetes
Not affected
Red Hat OpenShift Container Platform 3.9
openshift-elasticsearch-plugin
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-elasticsearch5
Not affected
Red Hat Process Automation 7
okhttp
Not affected
Red Hat Single Sign-On 7
okhttp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Decision Manager 7 | okhttp | Not affected | n/a |
| Red Hat Fuse 7 | okhttp | Not affected | n/a |
| Red Hat OpenShift Application Runtimes | okhttp | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | elasticsearch-cloud-kubernetes | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | openshift-elasticsearch-plugin | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-elasticsearch5 | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | elasticsearch-cloud-kubernetes | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | openshift-elasticsearch-plugin | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-elasticsearch5 | Not affected | n/a |
| Red Hat Process Automation 7 | okhttp | Not affected | n/a |
| Red Hat Single Sign-On 7 | okhttp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
OkHttp is used by OpenShift Container Platform in the Aggregated Logging stack. This issue is not considered a vulnerability for OpenShift Container Platform as the prerequisite for exploitation is the ability to inject code into the application.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.48% (0.02477) | 83.99th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.48% (0.02477) | 82.42th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.30% (0.00305) | 53.24th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.39% (0.01388) | 78.68th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.30% (0.00305) | 51.53th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.22% (0.00222) | 61.37th | v3 (v2023.03.01) |
| Apr 11, 2024 | 0.22% (0.00220) | 59.58th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.21% (0.00207) | 56.84th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.69% (0.02686) | 62.66th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.28% (0.03281) | 66.54th | v5 (v2026.06.15) |
| Apr 14, 2021 | 3.28% (0.03281) | 0.00th | v1 |
References (19)
- https://access.redhat.com/security/cve/CVE-2018-20200 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1709379 Issue Tracking
- https://cxsecurity.com/issue/WLB-2018120252 x_refsource_MISCExploitThird Party Advisory
- https://github.com/square/okhttp/commits/master x_refsource_MISCPatchThird Party Advisory
- https://github.com/square/okhttp/issues/4967 x_refsource_MISC
- https://github.com/square/okhttp/releases x_refsource_MISCProduct
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r0dd7ff197b2e3bdd80a0326587ca3d0c22e10d1dba17c769d6da7d7a%40%3Cuser.flink.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r71100f23778d72fbd8be8baa6baffc159b9c4f3fae3db4826bdc8ab8%40%3Cissues.flink.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r78bfce980843be61a55615a7680bbf7ac751a9b3515231eab2d32068%40%3Cissues.flink.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rc436d58531754ac8fe20340044566518ea4dce66aeff9193356a225d%40%3Cissues.flink.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/recce57e195fbdd856dcf1933c136a8a66d7b02e05e3580f44d75a640%40%3Cissues.flink.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfd1eed12ba2a5dff37229edd60fc84a25517815d848994146a15af91%40%3Cissues.flink.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2018-20200
- https://square.github.io/okhttp/3.x/okhttp/ x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-20200
Change history (0)
No recorded changes yet.