http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Commons-httpclient
Subscribe
|
|
Redhat
Subscribe
|
Developer Toolset
Subscribe
Jboss Bpms
Subscribe
Jboss Brms
Subscribe
Jboss Data Virtualization
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Soa Platform
Subscribe
Jboss Enterprise Web Framework
Subscribe
Jboss Enterprise Web Platform
Subscribe
Jboss Fuse Service Works
Subscribe
Jboss Operations Network
Subscribe
Rhev Manager
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-222-1 | commons-httpclient security update |
EUVD |
EUVD-2018-0479 | http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783. |
Github GHSA |
GHSA-2x83-r56g-cv47 | Improper certificate validation in org.apache.httpcomponents:httpclient |
Ubuntu USN |
USN-2769-1 | Apache Commons HttpClient vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T21:28:39.315Z
Reserved: 2012-12-06T00:00:00.000Z
Link: CVE-2012-6153
No data.
Status : Deferred
Published: 2014-09-04T17:55:04.623
Modified: 2025-04-12T10:46:40.837
Link: CVE-2012-6153
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN