httpclient5 is vulnerable to Improper Certificate Validation
91
Critical Risk
AbstractClientTlsStrategy.upgrade copies TLS parameters onto the SSL engine before HostnameVerificationPolicy.BUILTIN sets endpoint identification, so the built-in hostname check never reaches the async handshake. An attacker who can intercept traffic can present a certificate for a different name and impersonate the server. The classic client is unaffected. The fix sets the endpoint identification algorithm before those parameters are applied.
You are affected if you are using a version that falls within the vulnerable range and you use the async HttpClient, including the default TLS configuration.
httpclient5 is vulnerable to Improper Certificate Validation in versions 5.4 - 5.6.3.
Upgrade the org.apache.httpcomponents.client5:httpclient5 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.