com.ning:async-http-client
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.ning:async-http-clientpage 1 of 1
- CVE-2013-7397NONECVSS 0.0EG 0.0✓ Fixed in 1.9.02015-06-24
vulnerable: 1.0.0 ... 1.9.0-BETA9 (86 versions)
Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS server…
- CVE-2013-7398NONECVSS 0.0EG 0.0✓ Fixed in 1.9.02015-06-24
vulnerable: 1.0.0 ... 1.9.0-BETA9 (86 versions)
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attacker…
Check whether com.ning:async-http-client is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.ning:async-http-client CVEs against the assets you own.
Start Free Scan →