logo

CVE-2020-13956 org.apache.httpcomponents:httpclient

Package

Manager: maven
Name: org.apache.httpcomponents:httpclient
Vulnerable Version: >=0 <4.5.13 || >=5.0.0 <5.0.3

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00505 pctl0.65179

Details

Cross-site scripting in Apache HttpClient Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

Metadata

Created: 2021-06-03T23:40:23Z
Modified: 2022-02-08T22:02:43Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-7r82-7xv7-xcpj/GHSA-7r82-7xv7-xcpj.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-7r82-7xv7-xcpj
Finding: F008
Auto approve: 1