Apache HttpClient vulnerability (CVE-2020-13956)
Issue date: 13-04-2021Affects versions: 14.4, 13.4, 12.6
Security Issue ID
SECURITY-196
Affected Product Version(s)
14.4.0, 13.4.7, 12.6.14
Severity
medium
Description
CVE-2020-13956
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
Instructions
Customers are recommended to upgrade to the latest maintenance release. This can be done by simply incrementing the version number of the parent POM for the implementation project.