{"id":"GHSA-2x83-r56g-cv47","summary":"Improper certificate validation in org.apache.httpcomponents:httpclient","details":"http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.","aliases":["CVE-2012-6153"],"modified":"2024-12-02T05:45:19.775756Z","published":"2018-10-17T00:05:15Z","database_specific":{"github_reviewed_at":"2020-06-16T20:53:18Z","nvd_published_at":null,"cwe_ids":["CWE-20"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-6153"},{"type":"WEB","url":"https://github.com/apache/httpcomponents-client/commit/6e14fc146a66e0f3eb362f45f95d1a58ee18886a"},{"type":"WEB","url":"https://github.com/apache/httpcomponents-client/commit/b930227f907af1198765fc47beabbddae344ca7b"},{"type":"WEB","url":"https://access.redhat.com/solutions/1165533"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1129916"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2x83-r56g-cv47"},{"type":"WEB","url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05103564"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1098.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1833.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1834.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1835.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1836.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1891.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1892.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0125.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0158.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0675.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0720.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0765.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0850.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0851.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1888.html"},{"type":"WEB","url":"http://svn.apache.org/viewvc?view=revision&revision=1411705"},{"type":"WEB","url":"http://www.ubuntu.com/usn/USN-2769-1"}],"affected":[{"package":{"name":"org.apache.httpcomponents:httpclient","ecosystem":"Maven","purl":"pkg:maven/org.apache.httpcomponents/httpclient"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.3"}]}],"versions":["4.0","4.0-alpha1","4.0-alpha2","4.0-alpha3","4.0-alpha4","4.0-beta1","4.0-beta2","4.0.1","4.0.2","4.0.3","4.1","4.1-alpha1","4.1-alpha2","4.1-beta1","4.1.1","4.1.2","4.1.3","4.2","4.2-alpha1","4.2-beta1","4.2.1","4.2.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-2x83-r56g-cv47/GHSA-2x83-r56g-cv47.json"}}],"schema_version":"1.9.0"}