PT-2015-3574 · None · Async Http Client

Kishore Bhatia

·

Published

2015-05-11

·

Updated

2022-05-13

·

CVE-2013-7397

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Async Http Client versions prior to 1.9.0
Description The issue allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical configuration, as demonstrated by a configuration that does not send client certificates. This occurs because X.509 certificate verification is skipped unless both a keyStore location and a trustStore location are explicitly set.
Recommendations For versions prior to 1.9.0, ensure that both a keyStore location and a trustStore location are explicitly set to enable X.509 certificate verification and prevent man-in-the-middle attacks.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7397
GHSA-8H53-FJGG-G42G
MGASA-2015-0212

Affected Products

Async Http Client