Количество 5
Количество 5
CVE-2013-7398
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
CVE-2013-7398
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
CVE-2013-7398
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
CVE-2013-7398
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Htt ...
GHSA-5c66-6h6g-6q6m
Insufficient Verification of Data Authenticity in Async Http Client
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2013-7398 main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate. | CVSS2: 4.3 | 1% Низкий | больше 10 лет назад | |
CVE-2013-7398 main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate. | CVSS2: 5.8 | 1% Низкий | около 13 лет назад | |
CVE-2013-7398 main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate. | CVSS2: 4.3 | 1% Низкий | больше 10 лет назад | |
CVE-2013-7398 main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Htt ... | CVSS2: 4.3 | 1% Низкий | больше 10 лет назад | |
GHSA-5c66-6h6g-6q6m Insufficient Verification of Data Authenticity in Async Http Client | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу