PT-2013-1312 · Apache · Apache Httpclient

Published

2013-10-02

·

Updated

2022-05-13

·

CVE-2013-4366

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache HttpClient versions 4.3.x before 4.3.1
Description The issue is related to insufficient input validation in the X509HostnameVerifier of the Apache HttpClient client module. This could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability involves hostname verification and can be exploited by attackers via unspecified vectors.
Recommendations For Apache HttpClient versions 4.3.x before 4.3.1, ensure that the X509HostnameVerifier is properly set to prevent exploitation. As a temporary workaround, consider implementing additional validation for hostname verification until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02621
CVE-2013-4366
GHSA-PQWH-44JJ-P5RM

Affected Products

Apache Httpclient