CVEFinder.io

CVE-2014-3577

🔶 medium
🔍 Scan for this CVE
Summary

org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field.

CVSS Score
5.8
Medium
EPSS Score
9.2
Exploit Probability
Published Date
2014-08-21
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 32.9% of all 329,456 vulnerabilities in our database.

#221,102
Below average severity
Severity Percentile
Last Modified 2026-06-17
Source NVD 🔗

📦 Affected Products 2

🔗 References 47

http://packetstormsecurity.com/files/127913/Apache-H...
Exploit Third Party Advisory VDB Entry
http://seclists.org/fulldisclosure/2014/Aug/48
Exploit Mailing List Third Party Advisory
http://www.securityfocus.com/bid/69258
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1030812
Third Party Advisory VDB Entry

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-40542 ⚠️ high 7.3 0.1 Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-... 2026-04-22
CVE-2025-27820 ⚠️ high 7.5 0.1 A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host na... 2025-04-24
CVE-2020-13956 🔶 medium 5.3 0.5 Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request U... 2020-12-02
CVE-2013-4366 ⛔ critical 9.8 1.3 http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifie... 2017-10-30
CVE-2015-5262 🔶 medium 4.3 0.9 http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.t... 2015-10-27
CVE-2012-5783 🔶 medium 5.8 0.7 Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, d... 2012-11-04
These CVEs affect the same products