http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2017-10-30T19:00:00

Updated: 2024-08-06T16:38:01.984Z

Reserved: 2013-06-12T00:00:00

Link: CVE-2013-4366

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-10-30T19:29:00.280

Modified: 2024-11-21T01:55:26.033

Link: CVE-2013-4366

cve-icon Redhat

No data.