Search CVE reports


Toggle filters

11 – 13 of 13 results


CVE-2017-14063

Medium priority
Ignored

Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were...

1 affected package

async-http-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
async-http-client Not affected
Show less packages

CVE-2013-7398

Medium priority
Ignored

main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle...

1 affected package

async-http-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
async-http-client Not affected
Show less packages

CVE-2013-7397

Medium priority

Some fixes available 1 of 5

Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof...

1 affected package

async-http-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
async-http-client Not affected Not affected Not affected
Show less packages