CVE-2012-5783
commons-httpclient - security update
EPSS 9.3%
Description
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
How to fix CVE-2012-5783
To remediate CVE-2012-5783, upgrade the affected package to a fixed version below.
- Debian/commons-httpclient—upgrade to 3.1-10.1 or later
- Debian/commons-httpclient—upgrade to 3.1-9+deb6u1 or later
- —no fix listed
Is CVE-2012-5783 being exploited?
Moderate — EPSS is 9.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 3.1-10.1
- from 0, < 3.1-9+deb6u1
- >= 3.0