Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Httpclient
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-4366 1 Apache 1 Httpclient 2020-07-28 7.5 HIGH 9.8 CRITICAL
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.