Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v468-qcjx-r72w

Опубликовано: 22 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

Пакеты

Наименование

org.apache.httpcomponents.client5:httpclient5

maven
Затронутые версииВерсия исправления

>= 5.6-alpha1, < 5.6.1

5.6.1

EPSS

Процентиль: 37%
0.00456
Низкий

7.3 High

CVSS3

Дефекты

CWE-304

Связанные уязвимости

CVSS3: 7.3
ubuntu
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

CVSS3: 7.3
redhat
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

CVSS3: 7.3
nvd
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

CVSS3: 7.3
debian
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allow ...

EPSS

Процентиль: 37%
0.00456
Низкий

7.3 High

CVSS3

Дефекты

CWE-304