Apache HttpClient CVE-2013-4366 Security Bypass Vulnerability
BID:104848
Info
Apache HttpClient CVE-2013-4366 Security Bypass Vulnerability
| Bugtraq ID: | 104848 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4366 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2017 12:00AM |
| Updated: | Oct 30 2017 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Apache Httpclient 4.3 |
| Not Vulnerable: |
Apache Httpclient 4.3.1 |
Exploit / POC
Apache HttpClient CVE-2013-4366 Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache HttpClient CVE-2013-4366 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache HttpClient CVE-2013-4366 Security Bypass Vulnerability
References:
References:
- Apache Homepage (Apache)
- Ensure X509HostnameVerifier is never null (Apache)
- Release 4.3.6 (Apache)