Publish Advisories

GHSA-cfh5-3ghh-wfjx
GHSA-wqq4-5wpv-mx2g
This commit is contained in:
advisory-database[bot]
2023-10-27 21:03:32 +00:00
parent 0a2a21632f
commit 06d7eb4dad
2 changed files with 17 additions and 37 deletions
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cfh5-3ghh-wfjx",
"modified": "2023-10-27T15:30:16Z",
"modified": "2023-10-27T21:02:46Z",
"published": "2018-10-17T00:05:06Z",
"aliases": [
"CVE-2014-3577"
],
"summary": "Moderate severity vulnerability that affects org.apache.httpcomponents:httpclient",
"summary": "Improper Verification of Cryptographic Signature in org.apache.httpcomponents:httpclient",
"details": "org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a \"CN=\" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the \"foo,CN=www.apache.org\" string in the O field.",
"severity": [
@@ -49,14 +49,6 @@
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-cfh5-3ghh-wfjx"
},
{
"type": "WEB",
"url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05103564"
},
{
"type": "WEB",
"url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05363782"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E"
@@ -193,18 +185,6 @@
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2014/Aug/48"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/60466"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/60589"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/60713"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/10/06/1"
@@ -213,18 +193,6 @@
"type": "WEB",
"url": "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html"
},
{
"type": "WEB",
"url": "http://www.osvdb.org/110143"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/69258"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id/1030812"
},
{
"type": "WEB",
"url": "http://www.ubuntu.com/usn/USN-2769-1"
@@ -235,7 +203,7 @@
"CWE-347"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:31:17Z",
"nvd_published_at": "2014-08-21T14:55:00Z"
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wqq4-5wpv-mx2g",
"modified": "2023-10-25T18:32:19Z",
"modified": "2023-10-27T21:01:50Z",
"published": "2023-10-16T14:05:37Z",
"aliases": [
"CVE-2023-45143"
@@ -67,6 +67,18 @@
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/"
}
],
"database_specific": {
@@ -74,7 +86,7 @@
"CWE-200"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed": true,
"github_reviewed_at": "2023-10-16T14:05:37Z",
"nvd_published_at": null
}