Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improper Certificate Validation (CVE-2012-5783) #78

Open
vdenotaris opened this issue Oct 2, 2019 · 0 comments
Open

Improper Certificate Validation (CVE-2012-5783) #78

vdenotaris opened this issue Oct 2, 2019 · 0 comments
Assignees
Labels
kind/bug Categorizes issue or pull request as related to a bug. priority/important-soon Must be staffed and worked on either currently, or very soon, ideally in time for the next release.

Comments

@vdenotaris
Copy link
Owner

Improper Certificate Validation
commons-httpclient:commons-httpclient is a component of the Apache HttpComponents project.

Affected versions of this package are vulnerable to Man-in-the-Middle attacks due to not verifying that the requesting server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate. This allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Depending on

@vdenotaris vdenotaris self-assigned this Oct 2, 2019
@vdenotaris vdenotaris added kind/bug Categorizes issue or pull request as related to a bug. priority/important-soon Must be staffed and worked on either currently, or very soon, ideally in time for the next release. labels Oct 2, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Categorizes issue or pull request as related to a bug. priority/important-soon Must be staffed and worked on either currently, or very soon, ideally in time for the next release.
Projects
None yet
Development

No branches or pull requests

1 participant