CVE-2020-13956Medium· 5.3▾ SunlitApache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 1.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
9.0%
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
httpclient < 4.5.13httpclient >= 5.0.0, < 5.0.3quarkus < 1.7.6data_integrator = 12.2.1.3.0data_integrator = 12.2.1.4.0jd_edwards_enterpriseone_orchestrator < 9.2.6.0jd_edwards_enterpriseone_tools < 9.2.6.0nosql_database < 20.3peoplesoft_enterprise_peopletools = 8.57peoplesoft_enterprise_peopletools = 8.58peoplesoft_enterprise_pt_peopletools = 8.57peoplesoft_enterprise_pt_peopletools = 8.58peoplesoft_enterprise_pt_peopletools = 8.59primavera_unifier >= 17.7, <= 17.12primavera_unifier = 16.1primavera_unifier = 16.2primavera_unifier = 18.8primavera_unifier = 19.12primavera_unifier = 20.12retail_customer_management_and_segmentation_foundation >= 16.0, <= 19.0spatial_studio < 20.1.1sql_developer < 20.4.1.407.0006active_iq_unified_managersnapcentercommerce_guided_search = 11.3.2communications_cloud_native_core_service_communication_proxy = 1.14.0sql_developer < 21.99weblogic_server = 12.2.1.4.0weblogic_server = 14.1.1.0.0Upgrade past the affected range:
httpclient 5.0.3quarkus 1.7.6jd_edwards_enterpriseone_orchestrator 9.2.6.0jd_edwards_enterpriseone_tools 9.2.6.0nosql_database 20.3spatial_studio 20.1.1sql_developer 21.99Connected by shared product, vendor, weakness, or advisory.
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups
CVE-2020-11987High· 8.2Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel
CVE-2021-29425Medium· 4.8In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…
CVE-2021-3572Medium· 5.7A flaw was found in python-pip in the way it handled Unicode separators in git references
CVE-2021-41079High· 7.5Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets
CVE-2023-46589High· 7.5Apache Tomcat Improper Input Validation vulnerability