cbcvebase.
CVE-2012-6153
published 2014-09-04

CVE-2012-6153: http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the…

PriorityP426medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
5.84%
92.4th percentile
http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.

Affected

20 ranges
VendorProductVersion rangeFixed in
apachecommons-httpclient>= 0 < 3.1-10.23.1-10.2
apachecommons-httpclient>= 0 < 3.1-10.23.1-10.2
apachecommons-httpclient>= 0 < 3.1-10.23.1-10.2
apachecommons-httpclient>= 0 < 3.1-10.23.1-10.2
apachecommons-httpclient4.0 – 4.2.2
debiancommons-httpclient< commons-httpclient 3.1-10.2 (bookworm)commons-httpclient 3.1-10.2 (bookworm)
jenkinsclient_needs_to_be_updated_independently_from_the_plugin
jenkinsjenkins<= 2.73.1
jenkinsjenkins<= 2.83
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinsmailer_plugin
jenkinsmaven<= 2.17
jenkinsmaven_plugin
jenkinsplease_note_that_swarm_plugin
jenkinsscript_security_plugin
jenkinsswarm<= 3.4
jenkinsswarm_plugin
jenkinsupdating_just_the_plugin

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa5.8MEDIUM
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.