MEDIUM · 4.3

CVE-2013-7398

main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, ...

Vulnerability Description

main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Async-Http-Client ProjectAsync-Http-Client<= 1.9.0
RedhatJboss Fuse<= 6.1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-7398?

CVE-2013-7398 is a vulnerability with a CVSS score of 4.3 (MEDIUM). main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, ...

How severe is CVE-2013-7398?

CVE-2013-7398 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-7398?

Check the references section above for vendor advisories and patch information. Affected products include: Async-Http-Client Project Async-Http-Client, Redhat Jboss Fuse.