MGASA-2021-0314

Source
https://advisories.mageia.org/MGASA-2021-0314.html
Import Source
https://advisories.mageia.org/MGASA-2021-0314.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0314
Related
Published
2021-07-06T23:12:30Z
Modified
2021-07-06T21:59:12Z
Summary
Updated httpcomponents-client packages fix a security vulnerability
Details

Priyank Nigam discovered that HttpComponents Client could misinterpret malformed authority component in a request URI and pick the wrong target host for request execution (CVE-2020-13956).

References
Credits

Affected packages

Mageia:7 / httpcomponents-client

Package

Name
httpcomponents-client
Purl
pkg:rpm/mageia/httpcomponents-client?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.5.5-1.1.mga7

Ecosystem specific

{
    "section": "core"
}