CVE-2013-7398
Insufficient Verification of Data Authenticity in Async Http Client
EPSS 1.0%
Description
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
How to fix CVE-2013-7398
To remediate CVE-2013-7398, upgrade the affected package to a fixed version below.
- Maven/com.ning:async-http-client—upgrade to 1.9.0 or later
Is CVE-2013-7398 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.9.0