Apache HttpClient vulnerability (CVE-2020-13956) 

Issue date: 13-04-2021
Affects versions: 14.4, 13.4, 12.6

Security Issue ID

SECURITY-196

 

Affected Product Version(s)

14.4.0, 13.4.7, 12.6.14


Severity 

medium
Description

CVE-2020-13956
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

Instructions

Customers are recommended to upgrade to the latest maintenance release. This can be done by simply incrementing the version number of the parent POM for the implementation project.