CVE-2013-4366
published 2017-10-30CVE-2013-4366: http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers…
PriorityP339critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.18%
80.3th percentile
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | httpclient | — | — |
| debian | httpcomponents-client | < httpcomponents-client 4.3.2-1 (bookworm) | httpcomponents-client 4.3.2-1 (bookworm) |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-4366: httpcomponents-client - http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 ...
vendor_debian·2013·CVSS 9.8
CVE-2013-4366 [CRITICAL] CVE-2013-4366: httpcomponents-client - http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 ...
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
Scope: local
bookworm: resolved (fixed in 4.3.2-1)
bullseye: resolved (fixed in 4.3.2-1)
forky: resolved (fixed in 4.3.2-1)
sid: resolved (fixed in 4.3.2-1)
trixie: resolved (fixed in 4.3.2-1)
GHSA
Hostname verification in Apache HttpClient 4.3 was disabled by default
ghsa·2022-05-13
CVE-2013-4366 [CRITICAL] CWE-20 Hostname verification in Apache HttpClient 4.3 was disabled by default
Hostname verification in Apache HttpClient 4.3 was disabled by default
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
OSV
Hostname verification in Apache HttpClient 4.3 was disabled by default
osv·2022-05-13
CVE-2013-4366 [CRITICAL] Hostname verification in Apache HttpClient 4.3 was disabled by default
Hostname verification in Apache HttpClient 4.3 was disabled by default
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
OSV
CVE-2013-4366: http/impl/client/HttpClientBuilder
osv·2017-10-30·CVSS 9.8
CVE-2013-4366 [CRITICAL] CVE-2013-4366: http/impl/client/HttpClientBuilder
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-30
Published