cbcvebase.
CVE-2020-13956
published 2020-12-02

CVE-2020-13956: Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttpclient< 4.5.134.5.13
apachehttpclient>= 5.0.0 < 5.0.35.0.3
debianhttpcomponents-client< httpcomponents-client 4.5.13-1 (bookworm)httpcomponents-client 4.5.13-1 (bookworm)
oraclecommerce_guided_search
oraclecommunications_cloud_native_core_service_communication_proxy
oracledata_integrator
oracledata_integrator
oraclejd_edwards_enterpriseone_orchestrator< 9.2.6.09.2.6.0
oraclejd_edwards_enterpriseone_tools< 9.2.6.09.2.6.0
oraclenosql_database< 20.320.3
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_pt_peopletools
oraclepeoplesoft_enterprise_pt_peopletools
oraclepeoplesoft_enterprise_pt_peopletools
oracleprimavera_unifier
oracleprimavera_unifier
oracleprimavera_unifier
oracleprimavera_unifier
oracleprimavera_unifier
oracleprimavera_unifier17.7 – 17.12
oracleretail_customer_management_and_segmentation_foundation16.0 – 19.0
oraclespatial_studio< 20.1.120.1.1
oraclesql_developer< 20.4.1.407.000620.4.1.407.0006
oraclesql_developer< 21.9921.99

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
ghsa5.3MEDIUM
osv5.3MEDIUM