CVE-2013-1909 in Red Hat and Apache Products
Published on August 23, 2013
The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Products Associated with CVE-2013-1909
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2013-1909 are published in these products:
Exploit Probability
EPSS
0.81%
Percentile
73.86%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.