Lucene search

K
osvGoogleOSV:GHSA-PQWH-44JJ-P5RM
HistoryMay 13, 2022 - 1:25 a.m.

Hostname verification in Apache HttpClient 4.3 was disabled by default

2022-05-1301:25:03
Google
osv.dev
15

0.001 Low

EPSS

Percentile

45.2%

http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.

0.001 Low

EPSS

Percentile

45.2%