Back

MEDIUM

async-http-client: missing hostname verification for SSL certificates

Published Jun 24, 2015

Description

main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 24, 2015
Updated Aug 6, 2024
Reserved Aug 25, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 9, 2013
GHSA-5C66-6H6G-6Q6M