Description
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
Published: 2017-10-30
Score: 9.8 Critical
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-4812 http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
Github GHSA Github GHSA GHSA-pqwh-44jj-p5rm Hostname verification in Apache HttpClient 4.3 was disabled by default
History

No history.

Subscriptions

Apache Httpclient
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T16:38:01.984Z

Reserved: 2013-06-12T00:00:00.000Z

Link: CVE-2013-4366

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-10-30T19:29:00.280

Modified: 2025-04-20T01:37:25.860

Link: CVE-2013-4366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses