Executive brief
Hostname verification in Apache HttpClient 4.3 was disabled by default
Affected products
- Maven org.apache.httpcomponents:httpclient
Junglewise Threat Intelligence
CVE-2013-4366 · Severity: low · CVSS 3.1 · Published 2022-05-13
Technologies: org.apache.httpcomponents:httpclient (Maven). Vendors: Maven.
Hostname verification in Apache HttpClient 4.3 was disabled by default