SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-13956

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

MEDIUM 5.3EPSS 9.03%

Does this matter?

Lower severity and a low EPSS score (9.03%). Track it; it rarely justifies an emergency change on its own.

Description

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
9.03% probability · 95th percentile
CISA KEV
Not listed
Affected
apache/httpclient · quarkus/quarkus · oracle/data integrator · oracle/jd edwards enterpriseone orchestrator · oracle/jd edwards enterpriseone tools · oracle/nosql database · oracle/peoplesoft enterprise peopletools · oracle/peoplesoft enterprise pt peopletools · oracle/primavera unifier · oracle/retail customer management and segmentation foundation · oracle/spatial studio · oracle/sql developer · netapp/active iq unified manager · netapp/snapcenter · oracle/commerce guided search · oracle/communications cloud native core service communication proxy · oracle/weblogic server
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.