Логотип exploitDog
bind:CVE-2013-7397
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2013-7397

Количество 5

Количество 5

ubuntu логотип

CVE-2013-7397

больше 10 лет назад

Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC configuration, as demonstrated by a configuration that does not send client certificates.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2013-7397

больше 12 лет назад

Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC configuration, as demonstrated by a configuration that does not send client certificates.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2013-7397

больше 10 лет назад

Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC configuration, as demonstrated by a configuration that does not send client certificates.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-7397

больше 10 лет назад

Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X. ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-8h53-fjgg-g42g

больше 3 лет назад

Insufficient Verification of Data Authenticity in Async Http Client

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-7397

Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC configuration, as demonstrated by a configuration that does not send client certificates.

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
redhat логотип
CVE-2013-7397

Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC configuration, as demonstrated by a configuration that does not send client certificates.

CVSS2: 5.8
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-7397

Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC configuration, as demonstrated by a configuration that does not send client certificates.

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2013-7397

Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X. ...

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
github логотип
GHSA-8h53-fjgg-g42g

Insufficient Verification of Data Authenticity in Async Http Client

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу