org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subjects Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a CN= string in a field in the distinguished name (DN) of a certificate, as demonstrated by the foo,CN=www.apache.org string in the O field.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Httpclient | Apache | 4.0 (including) | 4.3.4 (including) |
JBEWP 5 for RHEL 5 | RedHat | jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el5 | * |
JBEWP 5 for RHEL 5 | RedHat | jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el5 | * |
JBEWP 5 for RHEL 5 | RedHat | apache-cxf-0:2.2.12-14.patch_09.ep5.el5 | * |
JBEWP 5 for RHEL 6 | RedHat | jakarta-commons-httpclient-1:3.1-4_patch_02.el6_5 | * |
JBEWP 5 for RHEL 6 | RedHat | jboss-seam2-0:2.2.6.EAP5-22_patch_01.el6 | * |
JBEWP 5 for RHEL 6 | RedHat | apache-cxf-0:2.2.12-14.patch_09.el6 | * |
Red Hat Enterprise Linux 5 | RedHat | jakarta-commons-httpclient-1:3.0-7jpp.4.el5_10 | * |
Red Hat Enterprise Linux 6 | RedHat | jakarta-commons-httpclient-1:3.1-0.9.el6_5 | * |
Red Hat Enterprise Linux 7 | RedHat | httpcomponents-client-0:4.2.5-5.el7_0 | * |
Red Hat Enterprise Linux 7 | RedHat | jakarta-commons-httpclient-1:3.1-16.el7_0 | * |
Red Hat JBoss A-MQ 6.2 | RedHat | * | |
Red Hat JBoss A-MQ 6.2 | RedHat | * | |
Red Hat JBoss BPMS 6.0 | RedHat | jakarta-commons-httpclient | * |
Red Hat JBoss BPMS 6.0 | RedHat | httpclient | * |
Red Hat JBoss BPMS 6.0 | RedHat | cxf | * |
Red Hat JBoss BPMS 6.0 | RedHat | jakarta-commons-httpclient | * |
Red Hat JBoss BRMS 6.0 | RedHat | jakarta-commons-httpclient | * |
Red Hat JBoss BRMS 6.0 | RedHat | httpclient | * |
Red Hat JBoss BRMS 6.0 | RedHat | cxf | * |
Red Hat JBoss BRMS 6.0 | RedHat | jakarta-commons-httpclient | * |
Red Hat JBoss Data Virtualization 6.0 | RedHat | httpclient | * |
Red Hat JBoss Data Virtualization 6.1 | RedHat | * | |
Red Hat JBoss Enterprise Application Platform 5.2 | RedHat | httpclient | * |
Red Hat JBoss Enterprise Application Platform 5.2 | RedHat | jakarta-commons-httpclient | * |
Red Hat JBoss Enterprise Application Platform 5.2 | RedHat | * | |
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 | RedHat | jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el4 | * |
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 | RedHat | jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el4 | * |
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 | RedHat | apache-cxf-0:2.2.12-14.patch_09.ep5.el4 | * |
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 | RedHat | jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el5 | * |
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 | RedHat | jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el5 | * |
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 | RedHat | apache-cxf-0:2.2.12-14.patch_09.ep5.el5 | * |
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 | RedHat | jakarta-commons-httpclient-1:3.1-4_patch_02.el6_5 | * |
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 | RedHat | jboss-seam2-0:2.2.6.EAP5-22_patch_01.el6 | * |
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 | RedHat | apache-cxf-0:2.2.12-14.patch_09.el6 | * |
Red Hat JBoss Enterprise Application Platform 6.3 | RedHat | * | |
Red Hat JBoss Enterprise Application Platform 6.3 | RedHat | * | |
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5 | RedHat | httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el5 | * |
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5 | RedHat | apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el5 | * |
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5 | RedHat | wss4j-0:1.6.16-2.redhat_3.1.ep6.el5 | * |
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6 | RedHat | httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el6 | * |
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6 | RedHat | apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el6 | * |
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6 | RedHat | wss4j-0:1.6.16-2.redhat_3.1.ep6.el6 | * |
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 | RedHat | httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el7 | * |
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 | RedHat | apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el7 | * |
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 | RedHat | wss4j-0:1.6.16-2.redhat_3.1.ep6.el7 | * |
Red Hat JBoss Fuse 6.2 | RedHat | * | |
Red Hat JBoss Fuse 6.2 | RedHat | * | |
Red Hat JBoss Fuse Service Works 6.0 | RedHat | httpclient | * |
Red Hat JBoss Operations Network 3.3 | RedHat | httpclient | * |
Red Hat JBoss Operations Network 3.3 | RedHat | jakarta-commons-httpclient | * |
Red Hat JBoss Portal 6.2 | RedHat | httpclient | * |
Red Hat JBoss SOA Platform 5.3 | RedHat | cxf | * |
Red Hat JBoss SOA Platform 5.3 | RedHat | jakarta-commons-httpclient | * |
Red Hat JBoss Web Framework Kit 2.7 | RedHat | httpclient | * |
Red Hat JBoss Web Platform 5.2 | RedHat | httpclient | * |
Red Hat JBoss Web Platform 5.2 | RedHat | jakarta-commons-httpclient | * |
Red Hat JBoss Web Platform 5.2 | RedHat | * | |
Red Hat OpenShift Container Platform 4.10 | RedHat | jenkins-0:2.319.2.1643288987-1.el8 | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | activemq-0:5.9.0-6.redhat.611463.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | ImageMagick-0:6.7.2.7-5.el6_8 | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | jenkins-0:1.651.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | libcgroup-0:0.40.rc1-18.el6_8 | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-broker-0:1.16.3.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-broker-util-0:1.37.6.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-cron-0:1.25.4.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-diy-0:1.26.2.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-haproxy-0:1.31.6.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-jbosseap-0:2.27.4.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-jbossews-0:1.35.5.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-jenkins-0:1.29.2.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-jenkins-client-0:1.26.1.1-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-mongodb-0:1.26.2.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-mysql-0:1.31.3.3-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-nodejs-0:1.33.1.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-perl-0:1.30.2.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-php-0:1.35.4.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-python-0:1.34.3.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-cartridge-ruby-0:1.32.2.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-msg-node-mcollective-0:1.30.2.2-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-node-proxy-0:1.26.3.1-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | openshift-origin-node-util-0:1.38.7.1-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | rhc-0:1.38.7.1-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | rubygem-openshift-origin-admin-console-0:1.28.2.1-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | rubygem-openshift-origin-controller-0:1.38.6.4-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | rubygem-openshift-origin-frontend-haproxy-sni-proxy-0:0.5.2.1-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | rubygem-openshift-origin-msg-broker-mcollective-0:1.36.2.4-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | rubygem-openshift-origin-node-0:1.38.6.4-1.el6op | * |
Red Hat OpenShift Enterprise 2.2 | RedHat | rubygem-openshift-origin-routing-daemon-0:0.26.6.1-1.el6op | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 | RedHat | thermostat1-httpcomponents-client-0:4.2.5-3.4.el6.1 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS | RedHat | thermostat1-httpcomponents-client-0:4.2.5-3.4.el6.1 | * |
RHEV Manager version 3.5 | RedHat | org.ovirt.engine-root-0:3.5.0-29 | * |
Commons-httpclient | Ubuntu | precise | * |
Commons-httpclient | Ubuntu | trusty | * |
Commons-httpclient | Ubuntu | upstream | * |
Commons-httpclient | Ubuntu | vivid | * |
Httpcomponents-client | Ubuntu | precise | * |
Httpcomponents-client | Ubuntu | trusty | * |
Httpcomponents-client | Ubuntu | upstream | * |
Httpcomponents-client | Ubuntu | utopic | * |