http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://svn.apache.org/r1528614 | issue tracking release notes patch vendor advisory |
http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.3.x.txt | issue tracking release notes vendor advisory |