High severityNVD Advisory· Published Sep 4, 2014· Updated Jun 16, 2026
CVE-2012-6153
CVE-2012-6153
Description
http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.httpcomponents:httpclientMaven | < 4.2.3 | 4.2.3 |
Affected products
2Patches
Vulnerability mechanics
References
25- rhn.redhat.com/errata/RHSA-2014-1098.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2014-1833.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2014-1834.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2014-1835.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2014-1836.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2014-1891.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2014-1892.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2015-0125.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2015-0158.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2015-0675.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2015-0720.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2015-0765.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2015-0850.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2015-0851.htmlnvdThird Party AdvisoryWEB
- svn.apache.org/viewvcnvdVendor AdvisoryWEB
- www.securityfocus.com/bid/69257nvdThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-2769-1nvdThird Party AdvisoryWEB
- access.redhat.com/solutions/1165533nvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-2x83-r56g-cv47ghsaADVISORY
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2012-6153ghsaADVISORY
- rhn.redhat.com/errata/RHSA-2015-1888.htmlnvdWEB
- github.com/apache/httpcomponents-client/commit/6e14fc146a66e0f3eb362f45f95d1a58ee18886aghsaWEB
- github.com/apache/httpcomponents-client/commit/b930227f907af1198765fc47beabbddae344ca7bghsaWEB
News mentions
0No linked articles in our index yet.