ZeroHour

CVE-2020-13956

CVSS 3.1
5.3 medium
EPSS
9%p95
Published
()
Modified
Description

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

Vendors
apachequarkusoraclenetapp
Products
httpclient, quarkus, data integrator, jd edwards enterpriseone orchestrator, jd edwards enterpriseone tools, nosql database, peoplesoft enterprise peopletools, peoplesoft enterprise pt peopletools, primavera unifier, retail customer management and segmentation foundation, spatial studio, sql developer
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.