http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2017-10-30T19:00:00

Updated: 2024-08-06T16:38:01.984Z

Reserved: 2013-06-12T00:00:00

Link: CVE-2013-4366

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-10-30T19:29:00.280

Modified: 2020-07-28T13:44:03.843

Link: CVE-2013-4366

cve-icon Redhat

No data.