Описание
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
Отчет
In OpenShift Container Platform (OCP) the affected components are behind OpenShift OAuth authentication. This restricts access to the vulnerable httpclient library to authenticated users only. Additionally the vulnerable httpclient library is not used directly in OCP components, therefore the impact by this vulnerability is Low.
In OCP 4 there are no plans to maintain ose-logging-elasticsearch5 container, hence marked as wontfix.
In the Red Hat Enterprise Linux platforms, Maven 35 and 36 are affected via their respective httpcomponents-client
component.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat BPM Suite 6 | httpclient | Out of support scope | ||
Red Hat build of OpenJDK 11 | openjdk/openjdk-11-rhel7 | Affected | ||
Red Hat build of OpenJDK 1.8 | redhat-openjdk-18/openjdk18-openshift | Affected | ||
Red Hat CodeReady Studio 12 | httpclient | Will not fix | ||
Red Hat Enterprise Linux 7 | httpcomponents-client | Affected | ||
Red Hat Enterprise Linux 9 | httpcomponents-client | Not affected | ||
Red Hat Integration Service Registry | httpclient | Not affected | ||
Red Hat JBoss A-MQ 6 | httpclient | Out of support scope | ||
Red Hat JBoss BRMS 5 | httpclient | Out of support scope | ||
Red Hat JBoss BRMS 6 | httpclient | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misin ...
Security update for httpcomponents-client, httpcomponents-core
EPSS
5.3 Medium
CVSS3