CVE Vulnerabilities

CVE-2014-3577

Published: Aug 21, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
4.8 IMPORTANT
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM

org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subjects Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a CN= string in a field in the distinguished name (DN) of a certificate, as demonstrated by the foo,CN=www.apache.org string in the O field.

Affected Software

Name Vendor Start Version End Version
Httpclient Apache 4.0 (including) 4.3.4 (including)
JBEWP 5 for RHEL 5 RedHat jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el5 *
JBEWP 5 for RHEL 5 RedHat jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el5 *
JBEWP 5 for RHEL 5 RedHat apache-cxf-0:2.2.12-14.patch_09.ep5.el5 *
JBEWP 5 for RHEL 6 RedHat jakarta-commons-httpclient-1:3.1-4_patch_02.el6_5 *
JBEWP 5 for RHEL 6 RedHat jboss-seam2-0:2.2.6.EAP5-22_patch_01.el6 *
JBEWP 5 for RHEL 6 RedHat apache-cxf-0:2.2.12-14.patch_09.el6 *
Red Hat Enterprise Linux 5 RedHat jakarta-commons-httpclient-1:3.0-7jpp.4.el5_10 *
Red Hat Enterprise Linux 6 RedHat jakarta-commons-httpclient-1:3.1-0.9.el6_5 *
Red Hat Enterprise Linux 7 RedHat httpcomponents-client-0:4.2.5-5.el7_0 *
Red Hat Enterprise Linux 7 RedHat jakarta-commons-httpclient-1:3.1-16.el7_0 *
Red Hat JBoss A-MQ 6.2 RedHat *
Red Hat JBoss A-MQ 6.2 RedHat *
Red Hat JBoss BPMS 6.0 RedHat jakarta-commons-httpclient *
Red Hat JBoss BPMS 6.0 RedHat httpclient *
Red Hat JBoss BPMS 6.0 RedHat cxf *
Red Hat JBoss BPMS 6.0 RedHat jakarta-commons-httpclient *
Red Hat JBoss BRMS 6.0 RedHat jakarta-commons-httpclient *
Red Hat JBoss BRMS 6.0 RedHat httpclient *
Red Hat JBoss BRMS 6.0 RedHat cxf *
Red Hat JBoss BRMS 6.0 RedHat jakarta-commons-httpclient *
Red Hat JBoss Data Virtualization 6.0 RedHat httpclient *
Red Hat JBoss Data Virtualization 6.1 RedHat *
Red Hat JBoss Enterprise Application Platform 5.2 RedHat httpclient *
Red Hat JBoss Enterprise Application Platform 5.2 RedHat jakarta-commons-httpclient *
Red Hat JBoss Enterprise Application Platform 5.2 RedHat *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 RedHat jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el4 *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 RedHat jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el4 *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 RedHat apache-cxf-0:2.2.12-14.patch_09.ep5.el4 *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 RedHat jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el5 *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 RedHat jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el5 *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 RedHat apache-cxf-0:2.2.12-14.patch_09.ep5.el5 *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 RedHat jakarta-commons-httpclient-1:3.1-4_patch_02.el6_5 *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 RedHat jboss-seam2-0:2.2.6.EAP5-22_patch_01.el6 *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 RedHat apache-cxf-0:2.2.12-14.patch_09.el6 *
Red Hat JBoss Enterprise Application Platform 6.3 RedHat *
Red Hat JBoss Enterprise Application Platform 6.3 RedHat *
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5 RedHat httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el5 *
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5 RedHat apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el5 *
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5 RedHat wss4j-0:1.6.16-2.redhat_3.1.ep6.el5 *
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6 RedHat httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el6 *
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6 RedHat apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el6 *
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6 RedHat wss4j-0:1.6.16-2.redhat_3.1.ep6.el6 *
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 RedHat httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el7 *
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 RedHat apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el7 *
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 RedHat wss4j-0:1.6.16-2.redhat_3.1.ep6.el7 *
Red Hat JBoss Fuse 6.2 RedHat *
Red Hat JBoss Fuse 6.2 RedHat *
Red Hat JBoss Fuse Service Works 6.0 RedHat httpclient *
Red Hat JBoss Operations Network 3.3 RedHat httpclient *
Red Hat JBoss Operations Network 3.3 RedHat jakarta-commons-httpclient *
Red Hat JBoss Portal 6.2 RedHat httpclient *
Red Hat JBoss SOA Platform 5.3 RedHat cxf *
Red Hat JBoss SOA Platform 5.3 RedHat jakarta-commons-httpclient *
Red Hat JBoss Web Framework Kit 2.7 RedHat httpclient *
Red Hat JBoss Web Platform 5.2 RedHat httpclient *
Red Hat JBoss Web Platform 5.2 RedHat jakarta-commons-httpclient *
Red Hat JBoss Web Platform 5.2 RedHat *
Red Hat OpenShift Container Platform 4.10 RedHat jenkins-0:2.319.2.1643288987-1.el8 *
Red Hat OpenShift Enterprise 2.2 RedHat activemq-0:5.9.0-6.redhat.611463.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat ImageMagick-0:6.7.2.7-5.el6_8 *
Red Hat OpenShift Enterprise 2.2 RedHat jenkins-0:1.651.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat libcgroup-0:0.40.rc1-18.el6_8 *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-broker-0:1.16.3.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-broker-util-0:1.37.6.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-cron-0:1.25.4.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-diy-0:1.26.2.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-haproxy-0:1.31.6.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-jbosseap-0:2.27.4.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-jbossews-0:1.35.5.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-jenkins-0:1.29.2.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-jenkins-client-0:1.26.1.1-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-mongodb-0:1.26.2.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-mysql-0:1.31.3.3-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-nodejs-0:1.33.1.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-perl-0:1.30.2.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-php-0:1.35.4.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-python-0:1.34.3.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-cartridge-ruby-0:1.32.2.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-msg-node-mcollective-0:1.30.2.2-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-node-proxy-0:1.26.3.1-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat openshift-origin-node-util-0:1.38.7.1-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat rhc-0:1.38.7.1-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat rubygem-openshift-origin-admin-console-0:1.28.2.1-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat rubygem-openshift-origin-controller-0:1.38.6.4-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat rubygem-openshift-origin-frontend-haproxy-sni-proxy-0:0.5.2.1-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat rubygem-openshift-origin-msg-broker-mcollective-0:1.36.2.4-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat rubygem-openshift-origin-node-0:1.38.6.4-1.el6op *
Red Hat OpenShift Enterprise 2.2 RedHat rubygem-openshift-origin-routing-daemon-0:0.26.6.1-1.el6op *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 RedHat thermostat1-httpcomponents-client-0:4.2.5-3.4.el6.1 *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS RedHat thermostat1-httpcomponents-client-0:4.2.5-3.4.el6.1 *
RHEV Manager version 3.5 RedHat org.ovirt.engine-root-0:3.5.0-29 *
Commons-httpclient Ubuntu precise *
Commons-httpclient Ubuntu trusty *
Commons-httpclient Ubuntu upstream *
Commons-httpclient Ubuntu vivid *
Httpcomponents-client Ubuntu precise *
Httpcomponents-client Ubuntu trusty *
Httpcomponents-client Ubuntu upstream *
Httpcomponents-client Ubuntu utopic *

References