Vulnerabilities > Apache > Httpclient > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-10-30 CVE-2013-4366 Improper Input Validation vulnerability in Apache Httpclient 4.3
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
network
low complexity
apache CWE-20
critical
9.8