PT-2015-3574 · None · Async Http Client

Kishore Bhatia

·

Publicado

2015-05-11

·

Atualizado

2022-05-13

·

CVE-2013-7397

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Async Http Client versions prior to 1.9.0
Description The issue allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical configuration, as demonstrated by a configuration that does not send client certificates. This occurs because X.509 certificate verification is skipped unless both a keyStore location and a trustStore location are explicitly set.
Recommendations For versions prior to 1.9.0, ensure that both a keyStore location and a trustStore location are explicitly set to enable X.509 certificate verification and prevent man-in-the-middle attacks.

Correção

Insufficient Verification of Data Authenticity

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-7397
GHSA-8H53-FJGG-G42G
MGASA-2015-0212

Produtos afetados

Async Http Client