SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2013-4366

CRITICAL · CVSS 9.8 EPSS 2.18%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-10-30 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache, Java.

CVE
CVE-2013-4366
Severity
CRITICAL
CVSS
9.8
EPSS
2.18%
Apache Java

Original NVD Description

http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.

Related CVEs

Other vulnerabilities affecting the same vendor(s)