CVE-2013-7398
published 2015-06-24CVE-2013-7398: main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.83%
53.3th percentile
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| async-http-client_project | async-http-client | <= 1.9.0 | — |
| debian | async-http-client | — | — |
| jenkins | async_http_client_plugin | — | — |
| jenkins | build_failure_analyzer_plugin | — | — |
| jenkins | image_gallery_plugin | — | — |
| jenkins | tap_plugin | — | — |
| jenkins | users_of_build_failure_analyzer_plugin | — | — |
| jenkins | users_of_image_gallery_plugin | — | — |
| jenkins | users_of_tap_plugin | — | — |
| redhat | jboss_fuse | <= 6.1.0 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Jenkins
Jenkins Security Advisory 2016-06-20
vendor_jenkins·2016-06-20·CVSS 4.3
CVE-2013-7397 [MEDIUM] Jenkins Security Advisory 2016-06-20
Title: Jenkins Security Advisory 2016-06-20
Jenkins Security Advisory 2016-06-20
This advisory announces vulnerabilities in these Jenkins plugins:
Async Http Client Plugin
Build Failure Analyzer
Image Gallery Plugin
TAP Plugin
Description
Path traversal vulnerability in TAP Plugin
SECURITY-85 / CVE-2016-4986
The plugin did not correctly filter a parameter and allowed reading arbitrary files on the file system.
Path traversal vulnerability in Image Gallery Plugin
SECURITY-278 / CVE-2016-4987
The plugin did not correctly validate form fields and allowed listing arbitrary directories and reading arbitrary files on the file system.
Cross-site scripting vulnerability in Build Failure Analyzer Plugin
SECURITY-290 / CVE-2016-49
Red Hat
async-http-client: missing hostname verification for SSL certificates
vendor_redhat·2013-01-09·CVSS 4.3
CVE-2013-7398 [MEDIUM] CWE-297 async-http-client: missing hostname verification for SSL certificates
async-http-client: missing hostname verification for SSL certificates
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
It was found that async-http-client did not verify that the server hostname matched the domain name in the subject's Common Name (CN) or subjectAltName field in X.509 certificates. This could allow a man-in-the-middle attacker to spoof an SSL server if they had a certificate that was valid for any domain name.
Package: async-http-client (Red Hat JBoss Data Virtualization 6) - Affected
Debian
CVE-2013-7398: async-http-client - main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (...
vendor_debian·2013·CVSS 4.3
CVE-2013-7398 [MEDIUM] CVE-2013-7398: async-http-client - main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (...
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
Scope: local
bookworm: resolved
bullseye: resolved
sid: resolved
OSV
Insufficient Verification of Data Authenticity in Async Http Client
osv·2022-05-13
CVE-2013-7398 [MEDIUM] Insufficient Verification of Data Authenticity in Async Http Client
Insufficient Verification of Data Authenticity in Async Http Client
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
GHSA
Insufficient Verification of Data Authenticity in Async Http Client
ghsa·2022-05-13
CVE-2013-7398 [MEDIUM] CWE-345 Insufficient Verification of Data Authenticity in Async Http Client
Insufficient Verification of Data Authenticity in Async Http Client
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-7398 async-http-client: missing hostname verification for SSL certificates [fedora-all]
bugzilla·2014-08-26·CVSS 4.3
CVE-2013-7398 [MEDIUM] CVE-2013-7398 async-http-client: missing hostname verification for SSL certificates [fedora-all]
CVE-2013-7398 async-http-client: missing hostname verification for SSL certificates [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2013-7398 async-http-client: missing hostname verification for SSL certificates
bugzilla·2014-08-26·CVSS 4.3
CVE-2013-7398 [MEDIUM] CVE-2013-7398 async-http-client: missing hostname verification for SSL certificates
CVE-2013-7398 async-http-client: missing hostname verification for SSL certificates
It was found that async-http-client did not verify that the server hostname matched the domain name in the subject's Common Name (CN) or subjectAltName field in X.509 certificates. This could allow a man-in-the-middle attacker to spoof an SSL server if they had a certificate that was valid for any domain name.
Discussion:
Upstream bug:
https://github.com/AsyncHttpClient/async-http-client/issues/197
Upstream patch commits:
https://github.com/wsargent/async-http-client/commit/db6716ad2f10f5c2d5124904725017b2ba8c3434
https://github.com/AsyncHttpClient/async-http-client/pull/525
---
Created async-http-client tracking bugs for this issue:
Affects: fedora-all [bug 1133787]
---
This issue has been addre
http://openwall.com/lists/oss-security/2014/08/26/1http://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1176.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1551.htmlhttp://www.securityfocus.com/bid/69317https://github.com/AsyncHttpClient/async-http-client/issues/197https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3Ehttps://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-06-20http://openwall.com/lists/oss-security/2014/08/26/1http://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1176.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1551.htmlhttp://www.securityfocus.com/bid/69317https://github.com/AsyncHttpClient/async-http-client/issues/197https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3Ehttps://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-06-20
2015-06-24
Published