This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Apache First view 2014-08-21
Product Httpclient Last view 2020-12-02
Version * Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:apache:httpclient

Activity : Overall

Related : CVE

  Date Alert Description
5.3 2020-12-02 CVE-2020-13956

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

4.3 2015-10-27 CVE-2015-5262

http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.

5.8 2014-08-21 CVE-2014-3577

org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-399 Resource Management Errors

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2016-10-31 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_ac18046c9b0811e68011005056925db4.nasl - Type: ACT_GATHER_INFO
2015-10-15 Name: The remote Ubuntu host is missing a security-related patch.
File: ubuntu_USN-2769-1.nasl - Type: ACT_GATHER_INFO
2015-10-02 Name: The remote Fedora host is missing a security update.
File: fedora_2015-15590.nasl - Type: ACT_GATHER_INFO
2015-10-02 Name: The remote Fedora host is missing a security update.
File: fedora_2015-15589.nasl - Type: ACT_GATHER_INFO
2015-10-02 Name: The remote Fedora host is missing a security update.
File: fedora_2015-15588.nasl - Type: ACT_GATHER_INFO
2015-10-02 Name: The remote Debian host is missing a security update.
File: debian_DLA-322.nasl - Type: ACT_GATHER_INFO
2015-09-01 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2015-0158.nasl - Type: ACT_GATHER_INFO
2015-05-20 Name: The remote Debian host is missing a security update.
File: debian_DLA-222.nasl - Type: ACT_GATHER_INFO
2015-04-17 Name: The remote Windows host has web portal software installed that is affected by...
File: websphere_portal_8_0_0_1_cf15.nasl - Type: ACT_GATHER_INFO
2014-12-22 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2014-2019.nasl - Type: ACT_GATHER_INFO
2014-11-12 Name: The remote Red Hat host is missing a security update.
File: redhat-RHSA-2014-1834.nasl - Type: ACT_GATHER_INFO
2014-11-12 Name: The remote Red Hat host is missing a security update.
File: redhat-RHSA-2014-1833.nasl - Type: ACT_GATHER_INFO
2014-10-12 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2014-410.nasl - Type: ACT_GATHER_INFO
2014-10-01 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2014-1321.nasl - Type: ACT_GATHER_INFO
2014-10-01 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2014-1320.nasl - Type: ACT_GATHER_INFO
2014-09-09 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2014-1166.nasl - Type: ACT_GATHER_INFO
2014-09-09 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2014-1166.nasl - Type: ACT_GATHER_INFO
2014-09-09 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2014-1166.nasl - Type: ACT_GATHER_INFO
2014-09-08 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2014-1162.nasl - Type: ACT_GATHER_INFO
2014-09-04 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2014-1146.nasl - Type: ACT_GATHER_INFO
2014-09-04 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2014-1146.nasl - Type: ACT_GATHER_INFO
2014-09-04 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2014-1146.nasl - Type: ACT_GATHER_INFO
2014-08-30 Name: The remote Fedora host is missing a security update.
File: fedora_2014-9629.nasl - Type: ACT_GATHER_INFO
2014-08-30 Name: The remote Fedora host is missing a security update.
File: fedora_2014-9617.nasl - Type: ACT_GATHER_INFO
2014-08-27 Name: The remote Fedora host is missing a security update.
File: fedora_2014-9539.nasl - Type: ACT_GATHER_INFO