Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3832-9276-x7gf

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Certificate Validation in Apache Commons HttpClient

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Note that the Commons HttpClient project is end of life. It has been replaced by the Apache HttpComponents project in its HttpClient and HttpCore modules. CVE-2012-5783 has been patched in v4.0 of the Apache HttpComponents HttpClient module.

Пакеты

Наименование

commons-httpclient:commons-httpclient

maven
Затронутые версииВерсия исправления

>= 3.0

Отсутствует

EPSS

Процентиль: 70%
0.00649
Низкий

Дефекты

CWE-295

Связанные уязвимости

ubuntu
около 13 лет назад

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS3: 3.7
redhat
около 13 лет назад

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

nvd
около 13 лет назад

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

debian
около 13 лет назад

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Ser ...

oracle-oval
больше 12 лет назад

ELSA-2013-0270: jakarta-commons-httpclient security update (MODERATE)

EPSS

Процентиль: 70%
0.00649
Низкий

Дефекты

CWE-295