http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade commons-httpclient | Jul 30, 2024 | Sep 4, 2014 |
| Freebsd | — | Upgrade axis2 | Dec 10, 2025 | Oct 28, 2016 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Jul 2, 2021 | Sep 4, 2014 |
| Jenkins 2017 10 11 | — | Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to version 2.84Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to version 2.73.2 | Nov 13, 2017 | Sep 4, 2014 |
| Jenkins 2017 10 11_cve 2017 1000396 | — | — | Nov 20, 2017 | Sep 4, 2014 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Aug 14, 2014 |
| Ubuntu | — | Upgrade libcommons-httpclient-java | Nov 8, 2024 | Sep 4, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub