org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
Jboss Amq
Subscribe
Jboss Bpms
Subscribe
Jboss Brms
Subscribe
Jboss Data Virtualization
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Soa Platform
Subscribe
Jboss Enterprise Web Framework
Subscribe
Jboss Enterprise Web Platform
Subscribe
Jboss Fuse
Subscribe
Jboss Fuse Service Works
Subscribe
Jboss Operations Network
Subscribe
Openshift
Subscribe
Rhel Software Collections
Subscribe
Rhev Manager
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-222-1 | commons-httpclient security update |
EUVD |
EUVD-2018-0575 | org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field. |
Github GHSA |
GHSA-cfh5-3ghh-wfjx | Improper Verification of Cryptographic Signature in org.apache.httpcomponents:httpclient |
Ubuntu USN |
USN-2769-1 | Apache Commons HttpClient vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T10:50:17.592Z
Reserved: 2014-05-14T00:00:00.000Z
Link: CVE-2014-3577
No data.
Status : Deferred
Published: 2014-08-21T14:55:05.100
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-3577
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN