CVE-2013-4366: Input Validation
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2013-4366?
CVE-2013-4366 is a vulnerability in Apache HttpClient 4.3.x before 4.3.1 that allows attackers to have unspecified impact via vectors involving hostname verification.
What is the severity of CVE-2013-4366?
The severity of CVE-2013-4366 is critical with a CVSS score of 9.8.
How does CVE-2013-4366 affect Apache HttpClient?
CVE-2013-4366 affects Apache HttpClient 4.3.x before 4.3.1 by not ensuring that X509HostnameVerifier is not null, which can be exploited by attackers.
How do I fix CVE-2013-4366?
To fix CVE-2013-4366, upgrade to Apache HttpClient version 4.3.1 or higher.
Where can I find more information about CVE-2013-4366?
You can find more information about CVE-2013-4366 on the Apache website and the official release notes for Apache HttpClient 4.3.x.