QID 981104
QID 981104: Java (maven) Security Update for org.apache.httpcomponents:httpclient (GHSA-fmj5-wv96-r2ch)
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fmj5-wv96-r2ch for updates pertaining to this vulnerability.
Vendor References
- GHSA-fmj5-wv96-r2ch -
github.com/advisories/GHSA-fmj5-wv96-r2ch
CVEs related to QID 981104
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fmj5-wv96-r2ch | org.apache.httpcomponents:httpclient |
|