Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-13956

Опубликовано: 02 дек. 2020
Источник: debian
EPSS Низкий

Описание

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
httpcomponents-clientfixed4.5.13-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1886587

  • Fixed by: https://github.com/apache/httpcomponents-client/commit/e628b4c5c464c2fa346385596cc78e035a91a62e (4.5.13-RC1)

EPSS

Процентиль: 66%
0.00505
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 5 лет назад

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

CVSS3: 5.3
redhat
больше 5 лет назад

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

CVSS3: 5.3
nvd
больше 5 лет назад

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

suse-cvrf
больше 1 года назад

Security update for httpcomponents-client, httpcomponents-core

rocky
почти 4 года назад

Moderate: maven:3.5 security update

EPSS

Процентиль: 66%
0.00505
Низкий