-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.axis2:axis2 | maven | <= 1.6.2 | 1.8.0 |
The vulnerability stems from Axis2's dependency on Apache HttpClient 3.x, which didn't enforce hostname verification by default. Key functions are: 1) SSLProtocolSocketFactory.createSocket in HttpClient 3.x, which handles SSL socket creation without hostname checks. 2) Axis2's transport layer using this vulnerable implementation. The JIRA ticket AXIS2-6018 confirms the root cause was HttpClient 3.x usage, fixed by upgrading to HttpClient 4.x in Axis2 1.8.0. These functions represent the critical points where proper validation was missing.
Ongoing coverage of React2Shell