Описание
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
A flaw was found in Apache HttpClient. This vulnerability allows unauthorized access or information disclosure via disabled Public Suffix List (PSL) validation, affecting cookie management and hostname verification.
Отчет
This vulnerability is rated Moderate due to the high attack complexity required for exploitation, the limited impact on confidentiality, and the fact that the issue does not allow direct system compromise or denial of service. While the failure to load the Public Suffix List weakens hostname and cookie validation, it does not lead to immediate critical security breaches, and mitigation techniques such as manual cookie domain validation and other security measures typically reduce the risk in real-world scenarios.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
AMQ Clients | httpclient5 | Fix deferred | ||
Cryostat 3 | httpclient5 | Not affected | ||
Cryostat 4 | httpclient5 | Not affected | ||
Red Hat AMQ Broker 7 | httpclient5 | Not affected | ||
Red Hat build of Apache Camel 4 for Quarkus 3 | quarkus-camel-bom | Not affected | ||
Red Hat build of Apache Camel 4 for Quarkus 3 | quarkus-cxf-bom | Not affected | ||
Red Hat build of Apache Camel for Spring Boot 4 | httpclient5 | Not affected | ||
Red Hat build of Apache Camel - HawtIO 4 | httpclient5 | Not affected | ||
Red Hat build of Apicurio Registry 2 | httpclient5 | Not affected | ||
Red Hat build of Apicurio Registry 3 | httpclient5 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
A bug in PSL validation logic in Apache HttpClient 5.4.x disables doma ...
Уязвимость механизма PSL validation клиентского модуля Apache HttpClient средства Apache HttpComponents, позволяющая нарушителю осуществить CSRF-атаку
EPSS
6.5 Medium
CVSS3