GHSA-pqwh-44jj-p5rm
CRITICALCVE-2013-4366http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
- Affected
- >= 4.3, < 4.3.1
- Fixed in
- 4.3.1
- Weakness
- CWE-20
- Published
- 2022-05-13
- Source
- github