Описание
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 3.1-11ubuntu1 |
| bionic | released | 3.1-11ubuntu1 |
| cosmic | released | 3.1-11ubuntu1 |
| devel | released | 3.1-11ubuntu1 |
| disco | released | 3.1-11ubuntu1 |
| eoan | released | 3.1-11ubuntu1 |
| esm-apps/bionic | released | 3.1-11ubuntu1 |
| esm-apps/focal | released | 3.1-11ubuntu1 |
| esm-apps/jammy | released | 3.1-11ubuntu1 |
| esm-apps/xenial | released | 3.1-11ubuntu1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | 4.4.1-1 |
| bionic | not-affected | 4.4.1-1 |
| cosmic | not-affected | 4.4.1-1 |
| devel | not-affected | 4.4.1-1 |
| disco | not-affected | 4.4.1-1 |
| eoan | not-affected | 4.4.1-1 |
| esm-apps/bionic | not-affected | 4.4.1-1 |
| esm-apps/focal | not-affected | 4.4.1-1 |
| esm-apps/jammy | not-affected | 4.4.1-1 |
| esm-apps/xenial | not-affected | 4.4.1-1 |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents ...
Denial of service vulnerability in org.apache.httpcomponents:httpclient
Уязвимость клиентского модуля Apache HttpClient средства Apache HttpComponents и операционных систем Fedora и Ubuntu, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
4.3 Medium
CVSS2