9.8
CVE-2013-4366
- EPSS 2.18%
- Veröffentlicht 30.10.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Httpclient Version 4.3
Apache ≫ Httpclient Version 4.3 Update alpha1
Apache ≫ Httpclient Version 4.3 Update beta1
Apache ≫ Httpclient Version 4.3 Update beta2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.18% | 0.805 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://svn.apache.org/r1528614
http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.3.x.txt