CVE Vulnerabilities

CVE-2014-3577

Published: Aug 21, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
4.8 IMPORTANT
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subjects Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a CN= string in a field in the distinguished name (DN) of a certificate, as demonstrated by the foo,CN=www.apache.org string in the O field.

Affected Software

NameVendorStart VersionEnd Version
HttpclientApache4.0 (including)4.3.4 (including)
JBEWP 5 for RHEL 5RedHatjakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el5*
JBEWP 5 for RHEL 5RedHatjboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el5*
JBEWP 5 for RHEL 5RedHatapache-cxf-0:2.2.12-14.patch_09.ep5.el5*
JBEWP 5 for RHEL 6RedHatjakarta-commons-httpclient-1:3.1-4_patch_02.el6_5*
JBEWP 5 for RHEL 6RedHatjboss-seam2-0:2.2.6.EAP5-22_patch_01.el6*
JBEWP 5 for RHEL 6RedHatapache-cxf-0:2.2.12-14.patch_09.el6*
Red Hat Enterprise Linux 5RedHatjakarta-commons-httpclient-1:3.0-7jpp.4.el5_10*
Red Hat Enterprise Linux 6RedHatjakarta-commons-httpclient-1:3.1-0.9.el6_5*
Red Hat Enterprise Linux 7RedHathttpcomponents-client-0:4.2.5-5.el7_0*
Red Hat Enterprise Linux 7RedHatjakarta-commons-httpclient-1:3.1-16.el7_0*
Red Hat JBoss A-MQ 6.2RedHat*
Red Hat JBoss A-MQ 6.2RedHat*
Red Hat JBoss BPMS 6.0RedHatjakarta-commons-httpclient*
Red Hat JBoss BPMS 6.0RedHathttpclient*
Red Hat JBoss BPMS 6.0RedHatcxf*
Red Hat JBoss BPMS 6.0RedHatjakarta-commons-httpclient*
Red Hat JBoss BRMS 6.0RedHatjakarta-commons-httpclient*
Red Hat JBoss BRMS 6.0RedHathttpclient*
Red Hat JBoss BRMS 6.0RedHatcxf*
Red Hat JBoss BRMS 6.0RedHatjakarta-commons-httpclient*
Red Hat JBoss Data Virtualization 6.0RedHathttpclient*
Red Hat JBoss Data Virtualization 6.1RedHat*
Red Hat JBoss Enterprise Application Platform 5.2RedHathttpclient*
Red Hat JBoss Enterprise Application Platform 5.2RedHatjakarta-commons-httpclient*
Red Hat JBoss Enterprise Application Platform 5.2RedHat*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4RedHatjakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el4*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4RedHatjboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el4*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4RedHatapache-cxf-0:2.2.12-14.patch_09.ep5.el4*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5RedHatjakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el5*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5RedHatjboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el5*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5RedHatapache-cxf-0:2.2.12-14.patch_09.ep5.el5*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6RedHatjakarta-commons-httpclient-1:3.1-4_patch_02.el6_5*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6RedHatjboss-seam2-0:2.2.6.EAP5-22_patch_01.el6*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6RedHatapache-cxf-0:2.2.12-14.patch_09.el6*
Red Hat JBoss Enterprise Application Platform 6.3RedHat*
Red Hat JBoss Enterprise Application Platform 6.3RedHat*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5RedHathttpcomponents-eap6-0:6-12.redhat_2.1.ep6.el5*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5RedHatapache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el5*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5RedHatwss4j-0:1.6.16-2.redhat_3.1.ep6.el5*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6RedHathttpcomponents-eap6-0:6-12.redhat_2.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6RedHatapache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6RedHatwss4j-0:1.6.16-2.redhat_3.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7RedHathttpcomponents-eap6-0:6-12.redhat_2.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7RedHatapache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7RedHatwss4j-0:1.6.16-2.redhat_3.1.ep6.el7*
Red Hat JBoss Fuse 6.2RedHat*
Red Hat JBoss Fuse 6.2RedHat*
Red Hat JBoss Fuse Service Works 6.0RedHathttpclient*
Red Hat JBoss Operations Network 3.3RedHathttpclient*
Red Hat JBoss Operations Network 3.3RedHatjakarta-commons-httpclient*
Red Hat JBoss Portal 6.2RedHathttpclient*
Red Hat JBoss SOA Platform 5.3RedHatcxf*
Red Hat JBoss SOA Platform 5.3RedHathttpclient*
Red Hat JBoss SOA Platform 5.3RedHatjakarta-commons-httpclient*
Red Hat JBoss Web Framework Kit 2.7RedHathttpclient*
Red Hat JBoss Web Platform 5.2RedHathttpclient*
Red Hat JBoss Web Platform 5.2RedHatjakarta-commons-httpclient*
Red Hat JBoss Web Platform 5.2RedHat*
Red Hat OpenShift Container Platform 4.10RedHatjenkins-0:2.319.2.1643288987-1.el8*
Red Hat OpenShift Enterprise 2.2RedHatactivemq-0:5.9.0-6.redhat.611463.el6op*
Red Hat OpenShift Enterprise 2.2RedHatImageMagick-0:6.7.2.7-5.el6_8*
Red Hat OpenShift Enterprise 2.2RedHatjenkins-0:1.651.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatlibcgroup-0:0.40.rc1-18.el6_8*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-broker-0:1.16.3.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-broker-util-0:1.37.6.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-cron-0:1.25.4.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-diy-0:1.26.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-haproxy-0:1.31.6.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-jbosseap-0:2.27.4.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-jbossews-0:1.35.5.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-jenkins-0:1.29.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-jenkins-client-0:1.26.1.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-mongodb-0:1.26.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-mysql-0:1.31.3.3-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-nodejs-0:1.33.1.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-perl-0:1.30.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-php-0:1.35.4.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-python-0:1.34.3.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-ruby-0:1.32.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-msg-node-mcollective-0:1.30.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-node-proxy-0:1.26.3.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-node-util-0:1.38.7.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrhc-0:1.38.7.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-admin-console-0:1.28.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-controller-0:1.38.6.4-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-frontend-haproxy-sni-proxy-0:0.5.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-msg-broker-mcollective-0:1.36.2.4-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-node-0:1.38.6.4-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-routing-daemon-0:0.26.6.1-1.el6op*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6RedHatthermostat1-httpcomponents-client-0:4.2.5-3.4.el6.1*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSRedHatthermostat1-httpcomponents-client-0:4.2.5-3.4.el6.1*
RHEV Manager version 3.5RedHatorg.ovirt.engine-root-0:3.5.0-29*
Commons-httpclientUbuntuesm-infra-legacy/trusty*
Commons-httpclientUbuntuprecise*
Commons-httpclientUbuntutrusty*
Commons-httpclientUbuntutrusty/esm*
Commons-httpclientUbuntuupstream*
Commons-httpclientUbuntuvivid*
Httpcomponents-clientUbuntuesm-infra-legacy/trusty*
Httpcomponents-clientUbuntuprecise*
Httpcomponents-clientUbuntutrusty*
Httpcomponents-clientUbuntutrusty/esm*
Httpcomponents-clientUbuntuupstream*
Httpcomponents-clientUbuntuutopic*

References