CVE-2012-5783

EPSS 0.62%

commons-httpclient - security update

發布日:2022/5/13修改日:2026/4/28

描述

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

受影響套件(3)

參考連結(18)