vulnerability
Amazon Linux AMI 2: CVE-2020-13956: Security patch for httpcomponents-client (ALAS-2023-1946)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:P/A:N) | Dec 2, 2020 | Feb 23, 2023 | Feb 23, 2023 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Dec 2, 2020
Added
Feb 23, 2023
Modified
Feb 23, 2023
Description
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
Solutions
amazon-linux-ami-2-upgrade-httpcomponents-clientamazon-linux-ami-2-upgrade-httpcomponents-client-javadoc
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.