CVE-2014-3577: Medium severity Apache HttpClient vulnerability
It was found that the fix for CVE-2012-6153 was incomplete: the code added to check that the server hostname matches the domain name in a subject's Common Name (CN) field in X.509 certificates was flawed. A man-in-the-middle attacker could use this flaw to spoof an SSL server using a specially crafted X.509 certificate.
Other sources
It was found that the fix for CVE-2012-6153 was incomplete. The code added to check that the server hostname matches the domain name in the subject's CN field was flawed. This can be exploited by a Man-in-the-middle (MITM) attack where the attacker can spoof a valid certificate using a specially crafted subject.
— Red Hat
org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jakarta-commons-httpclientto a version that resolves this vulnerability.Fixed in 1:3.1-4_patch_02.ep5.el5 - Upgrade
Upgrade
redhat/jboss-seam2to a version that resolves this vulnerability.Fixed in 0:2.2.6.EAP5-22_patch_01.ep5.el5 - Upgrade
Upgrade
redhat/apache-cxfto a version that resolves this vulnerability.Fixed in 0:2.2.12-14.patch_09.ep5.el5 - Upgrade
Upgrade
redhat/jakarta-commons-httpclientto a version that resolves this vulnerability.Fixed in 1:3.1-4_patch_02.el6_5 - Upgrade
Upgrade
redhat/jboss-seam2to a version that resolves this vulnerability.Fixed in 0:2.2.6.EAP5-22_patch_01.el6 - Upgrade
Upgrade
redhat/apache-cxfto a version that resolves this vulnerability.Fixed in 0:2.2.12-14.patch_09.el6 - Upgrade
Upgrade
redhat/jakarta-commons-httpclientto a version that resolves this vulnerability.Fixed in 1:3.0-7jpp.4.el5_10 - Upgrade
Upgrade
redhat/jakarta-commons-httpclientto a version that resolves this vulnerability.Fixed in 1:3.1-0.9.el6_5 - Upgrade
Upgrade
redhat/httpcomponents-clientto a version that resolves this vulnerability.Fixed in 0:4.2.5-5.el7_0 - Upgrade
Upgrade
redhat/jakarta-commons-httpclientto a version that resolves this vulnerability.Fixed in 1:3.1-16.el7_0 - Upgrade
Upgrade
redhat/jakarta-commons-httpclientto a version that resolves this vulnerability.Fixed in 1:3.1-4_patch_02.ep5.el4 - Upgrade
Upgrade
redhat/jboss-seam2to a version that resolves this vulnerability.Fixed in 0:2.2.6.EAP5-22_patch_01.ep5.el4 - Upgrade
Upgrade
redhat/apache-cxfto a version that resolves this vulnerability.Fixed in 0:2.2.12-14.patch_09.ep5.el4 - Upgrade
Upgrade
redhat/httpcomponents-eap6to a version that resolves this vulnerability.Fixed in 0:6-12.redhat_2.1.ep6.el5 - Upgrade
Upgrade
redhat/apache-cxfto a version that resolves this vulnerability.Fixed in 0:2.7.12-1.SP1_redhat_5.1.ep6.el5 - Upgrade
Upgrade
redhat/wss4jto a version that resolves this vulnerability.Fixed in 0:1.6.16-2.redhat_3.1.ep6.el5 - Upgrade
Upgrade
redhat/httpcomponents-eap6to a version that resolves this vulnerability.Fixed in 0:6-12.redhat_2.1.ep6.el6 - Upgrade
Upgrade
redhat/apache-cxfto a version that resolves this vulnerability.Fixed in 0:2.7.12-1.SP1_redhat_5.1.ep6.el6 - Upgrade
Upgrade
redhat/wss4jto a version that resolves this vulnerability.Fixed in 0:1.6.16-2.redhat_3.1.ep6.el6 - Upgrade
Upgrade
redhat/httpcomponents-eap6to a version that resolves this vulnerability.Fixed in 0:6-12.redhat_2.1.ep6.el7 - Upgrade
Upgrade
redhat/apache-cxfto a version that resolves this vulnerability.Fixed in 0:2.7.12-1.SP1_redhat_5.1.ep6.el7 - Upgrade
Upgrade
redhat/wss4jto a version that resolves this vulnerability.Fixed in 0:1.6.16-2.redhat_3.1.ep6.el7 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.319.2.1643288987-1.el8 - Upgrade
Upgrade
redhat/activemqto a version that resolves this vulnerability.Fixed in 0:5.9.0-6.redhat.611463.el6 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:1.651.2-1.el6 - Upgrade
Upgrade
redhat/libcgroupto a version that resolves this vulnerability.Fixed in 0:0.40.rc1-18.el6_8 - Upgrade
Upgrade
redhat/openshift-origin-brokerto a version that resolves this vulnerability.Fixed in 0:1.16.3.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-broker-utilto a version that resolves this vulnerability.Fixed in 0:1.37.6.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-cronto a version that resolves this vulnerability.Fixed in 0:1.25.4.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-diyto a version that resolves this vulnerability.Fixed in 0:1.26.2.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-haproxyto a version that resolves this vulnerability.Fixed in 0:1.31.6.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-jbosseapto a version that resolves this vulnerability.Fixed in 0:2.27.4.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-jbossewsto a version that resolves this vulnerability.Fixed in 0:1.35.5.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-jenkinsto a version that resolves this vulnerability.Fixed in 0:1.29.2.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-jenkins-clientto a version that resolves this vulnerability.Fixed in 0:1.26.1.1-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-mongodbto a version that resolves this vulnerability.Fixed in 0:1.26.2.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-mysqlto a version that resolves this vulnerability.Fixed in 0:1.31.3.3-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-nodejsto a version that resolves this vulnerability.Fixed in 0:1.33.1.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-perlto a version that resolves this vulnerability.Fixed in 0:1.30.2.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-phpto a version that resolves this vulnerability.Fixed in 0:1.35.4.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-pythonto a version that resolves this vulnerability.Fixed in 0:1.34.3.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-cartridge-rubyto a version that resolves this vulnerability.Fixed in 0:1.32.2.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-msg-node-mcollectiveto a version that resolves this vulnerability.Fixed in 0:1.30.2.2-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-node-proxyto a version that resolves this vulnerability.Fixed in 0:1.26.3.1-1.el6 - Upgrade
Upgrade
redhat/openshift-origin-node-utilto a version that resolves this vulnerability.Fixed in 0:1.38.7.1-1.el6 - Upgrade
Upgrade
redhat/rhcto a version that resolves this vulnerability.Fixed in 0:1.38.7.1-1.el6 - Upgrade
Upgrade
redhat/rubygem-openshift-origin-admin-consoleto a version that resolves this vulnerability.Fixed in 0:1.28.2.1-1.el6 - Upgrade
Upgrade
redhat/rubygem-openshift-origin-controllerto a version that resolves this vulnerability.Fixed in 0:1.38.6.4-1.el6 - Upgrade
Upgrade
redhat/rubygem-openshift-origin-frontend-haproxy-sni-proxyto a version that resolves this vulnerability.Fixed in 0:0.5.2.1-1.el6 - Upgrade
Upgrade
redhat/rubygem-openshift-origin-msg-broker-mcollectiveto a version that resolves this vulnerability.Fixed in 0:1.36.2.4-1.el6 - Upgrade
Upgrade
redhat/rubygem-openshift-origin-nodeto a version that resolves this vulnerability.Fixed in 0:1.38.6.4-1.el6 - Upgrade
Upgrade
redhat/rubygem-openshift-origin-routing-daemonto a version that resolves this vulnerability.Fixed in 0:0.26.6.1-1.el6 - Upgrade
Upgrade
redhat/thermostat1-httpcomponents-clientto a version that resolves this vulnerability.Fixed in 0:4.2.5-3.4.el6.1 - Upgrade
Upgrade
maven/org.apache.httpcomponents:httpclientto a version that resolves this vulnerability.Fixed in 4.3.5 - Upgrade
Upgrade
redhat/httpcomponents-clientto a version that resolves this vulnerability.Fixed in 4.3.5 - Upgrade
Upgrade
org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient/HttpAsyncClientto a version that resolves this vulnerability.Fixed in 4.3.5 - Upgrade
Upgrade
org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient/HttpAsyncClientto a version that resolves this vulnerability.Fixed in 4.0.2 - Compensating control
Mitigate MITM risk by restricting network access to only trusted endpoints and preventing attackers from intercepting/impersonating SSL servers (e.g., enforce network segmentation/ACLs so clients cannot reach untrusted hosts that could present spoofed certificates).
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2014:1320
- RHSA-2014:1833
- RHSA-2014:1166
- RHSA-2014:1146
- RHSA-2016:1931
- RHSA-2015:1177
- RHSA-2014:1892
- RHSA-2015:0234
- RHSA-2015:0851
- RHSA-2014:1891
- RHSA-2015:0235
- RHSA-2015:0850
- RHSA-2015:0765
- RHSA-2015:0675
- RHSA-2014:1323
- RHSA-2014:1836
- RHSA-2014:1321
- RHSA-2014:1834
- RHSA-2014:1163
- RHSA-2014:2020
- RHSA-2014:1162
- RHSA-2014:2019
- RHSA-2015:1176
- RHSA-2015:0720
- RHSA-2014:1904
- RHSA-2015:1009
- RHSA-2015:1888
- RHSA-2015:0125
- RHSA-2014:1322
- RHSA-2014:1835
- RHSA-2022:0055
- RHSA-2016:1773
- RHSA-2014:1082
- RHSA-2015:0158
- IBM-7279145
Frequently Asked Questions
What is the severity of CVE-2014-3577?
The severity of CVE-2014-3577 is classified as medium due to the potential for man-in-the-middle attacks.
How do I fix CVE-2014-3577?
To fix CVE-2014-3577, you should upgrade to Apache HttpClient version 4.3.5 or higher.
Which versions are affected by CVE-2014-3577?
Versions of Apache HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 are affected by CVE-2014-3577.
What is the impact of CVE-2014-3577?
CVE-2014-3577 allows attackers to perform man-in-the-middle attacks due to improper hostname verification.
Is CVE-2014-3577 exploitable remotely?
Yes, CVE-2014-3577 is exploitable remotely as it involves network communications that can be intercepted.