Codehaus XFire 1.2.5

CPE Details

Codehaus XFire 1.2.5
1.2.5
2012-11-05
18h35 +00:00
2012-11-13
17h56 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:codehaus:xfire:1.2.5:*:*:*:*:*:*:*

Informations

Vendor

codehaus

Product

xfire

Version

1.2.5

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2012-5817 2012-11-04 21h00 +00:00 Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
7.4
High