cbcvebase.
CVE-2015-5262
published 2015-10-27

CVE-2015-5262: http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an…

medium4.3CVSS 3.0
AVNACMAuNCNINAP
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttpclient4.3 – 4.3.5
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiancommons-httpclient< commons-httpclient 3.1-12 (bookworm)commons-httpclient 3.1-12 (bookworm)
debianhttpcomponents-client< commons-httpclient 3.1-12 (bookworm)commons-httpclient 3.1-12 (bookworm)
debianpython-pykmip< python-pykmip 0.7.0-3 (bookworm)python-pykmip 0.7.0-3 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
jenkinsazure_slave_plugin
jenkinsazure_vm_agents_plugin
jenkinscoverity_plugin
jenkinscppncss_plugin
jenkinscredentials_plugin
jenkinsenvinject_plugin
jenkinsenvironment_injector_plugin
jenkinsgerrit_trigger_plugin
jenkinsgit_plugin
jenkinsgoogle_play_android_publisher_plugin
jenkinsids_in_google_play_android_publisher_plugin
jenkinsimproper_access_control_in_gerrit_trigger_plugin
jenkinsjob_and_node_ownership_plugin
jenkinsmercurial_plugin
jenkinstestlink_plugin

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvd4.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa4.3MEDIUM
osv5.8MEDIUM