CVE-2013-7397: Medium severity redhat Jboss Fuse vulnerability
Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC configuration, as demonstrated by a configuration that does not send client certificates.
Other sources
It was found that async-http-client would disable SSL/TLS certificate verification under certain conditions, for example if HTTPS communication also uses client certificates. This can be exploited by a Man-in-the-middle (MITM) attack where the attacker can spoof a valid certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7397?
CVE-2013-7397 is classified as a High severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2013-7397?
To fix CVE-2013-7397, upgrade Async Http Client to version 1.9.0 or later.
Which versions of Async Http Client are affected by CVE-2013-7397?
Versions of Async Http Client earlier than 1.9.0 are affected by CVE-2013-7397.
Are there any specific software packages that include CVE-2013-7397?
Yes, CVE-2013-7397 affects software packages including Async Http Client, Red Hat JBoss Fuse, and others before version 1.9.0.
Can CVE-2013-7397 be exploited in production environments?
Yes, CVE-2013-7397 can be exploited in production environments if the vulnerable software is used without proper certificate verification.