Description
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
Remediation
References
http://svn.apache.org/r1528614
http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.3.x.txt
Related Vulnerabilities
CVE-2022-36079 Vulnerability in npm package parse-server
CVE-2022-29161 Vulnerability in maven package org.xwiki.platform:xwiki-platform-crypto
CVE-2019-15903 Vulnerability in npm package dbus
CVE-2020-36179 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-25721 Vulnerability in maven package com.veracode.jenkins:veracode-scan