Executive Summary

Informations
Name CVE-2013-7398 First vendor Publication 2015-06-24
Vendor Cve Last vendor Modification 2023-11-07

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Cvss Base Score 4.3 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7398

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-345 Insufficient Verification of Data Authenticity

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 2

Nessus® Vulnerability Scanner

Date Description
2015-05-11 Name : The remote Fedora host is missing a security update.
File : fedora_2015-6891.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fa...
https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2...
Source Url
BID http://www.securityfocus.com/bid/69317
CONFIRM https://github.com/AsyncHttpClient/async-http-client/issues/197
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-0...
MLIST http://openwall.com/lists/oss-security/2014/08/26/1
REDHAT http://rhn.redhat.com/errata/RHSA-2015-0850.html
http://rhn.redhat.com/errata/RHSA-2015-0851.html
http://rhn.redhat.com/errata/RHSA-2015-1176.html
http://rhn.redhat.com/errata/RHSA-2015-1551.html

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
Date Informations
2023-11-07 21:44:41
  • Multiple Updates
2021-05-05 01:14:12
  • Multiple Updates
2021-05-04 12:29:19
  • Multiple Updates
2021-04-22 01:35:33
  • Multiple Updates
2020-12-16 17:22:45
  • Multiple Updates
2020-05-24 01:13:05
  • Multiple Updates
2020-05-23 00:39:08
  • Multiple Updates
2019-04-17 00:19:07
  • Multiple Updates
2018-01-05 09:23:20
  • Multiple Updates
2017-02-10 09:23:38
  • Multiple Updates
2016-12-24 09:24:00
  • Multiple Updates
2016-11-29 00:24:50
  • Multiple Updates
2016-04-27 00:00:41
  • Multiple Updates
2015-07-22 05:29:30
  • Multiple Updates
2015-07-16 09:29:27
  • Multiple Updates
2015-07-13 21:27:06
  • Multiple Updates
2015-07-10 09:26:55
  • Multiple Updates
2015-06-25 21:26:21
  • Multiple Updates
2015-06-24 21:26:15
  • First insertion