Improper Certificate Validation Affecting commons-httpclient:commons-httpclient package, versions [,3.1-jenkins-1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.15% (52nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-COMMONSHTTPCLIENT-30083
  • published25 Mar 2013
  • disclosed4 Nov 2012
  • creditUnknown

Introduced: 4 Nov 2012

CVE-2012-5783  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade commons-httpclient:commons-httpclient to version 3.1-jenkins-1 or higher.

Overview

commons-httpclient:commons-httpclient is a HttpClient component of the Apache HttpComponents project.

Affected versions of this package are vulnerable to Improper Certificate Validation due to not verifying that the requesting server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate. This allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

NOTE: This plugin has been deprecated, but a fix has been released in version 3.1-jenkins-3 on a special Jenkins fork of the project.

CVSS Scores

version 3.1