CVE-2014-3577

Apache HttpComponents <4.3.5-4.0.2 - Man-in-the-middle

Title source: llm
STIX 2.1

Description

org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field.

References (47)

Core 47
Core References
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2014-1891.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-0765.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-0675.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-0720.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2014-1166.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2014-1833.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-0850.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-0158.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2014-1834.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-0125.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2014-1146.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2014-1892.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2014-1835.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2014-1836.html
Third Party Advisory, VDB Entry vdb-entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/95327
Exploit, Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2014/Aug/48
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2016-1773.html
Broken Link vdb-entry
http://www.osvdb.org/110143
Third Party Advisory third-party-advisory
http://secunia.com/advisories/60713
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-1888.html
Third Party Advisory third-party-advisory
http://secunia.com/advisories/60466
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-1176.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2016-1931.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-1177.html
Third Party Advisory, VDB Entry vdb-entry
http://www.securityfocus.com/bid/69258
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-0851.html
Third Party Advisory, VDB Entry vdb-entry
http://www.securitytracker.com/id/1030812
Third Party Advisory vendor-advisory
http://www.ubuntu.com/usn/USN-2769-1
Third Party Advisory third-party-advisory
http://secunia.com/advisories/60589

Scores

EPSS 0.0137
EPSS Percentile 80.5%

Details

Status published
Products (3)
apache/httpasyncclient 4.0 - 4.0.1
apache/httpclient 4.0 - 4.3.4
org.apache.httpcomponents/httpclient 0 - 4.3.5Maven
Published Aug 21, 2014
Tracked Since Feb 18, 2026