CVE-2020-13956

medium

Description

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

References

https://lists.apache.org/thread.html/r6dab7da30f8bf075f79ee189e33b45a197502e2676481bb8787fc0d7%40%3Cdev.hc.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.ranger.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.ranger.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.ranger.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.ranger.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccommits.pulsar.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.ranger.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Csolr-user.lucene.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccommits.turbine.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cgitbox.hive.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.hive.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.hive.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.hive.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.hive.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cgitbox.hive.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.solr.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.solr.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.solr.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.maven.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.maven.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.maven.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.drill.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.drill.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.drill.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.drill.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.drill.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.drill.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccommits.drill.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.drill.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.drill.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.drill.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccommits.creadur.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccommits.creadur.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccommits.creadur.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccommits.creadur.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccommits.creadur.apache.org%3E

https://www.oracle.com/security-alerts/cpuApr2021.html

https://lists.apache.org/thread.html/[email protected]%3Cissues.maven.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.creadur.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.solr.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.solr.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.jackrabbit.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.jackrabbit.apache.org%3E

https://www.oracle.com//security-alerts/cpujul2021.html

https://lists.apache.org/thread.html/[email protected]%3Cissues.solr.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.bookkeeper.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.bookkeeper.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.lucene.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.lucene.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.lucene.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.lucene.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.lucene.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.lucene.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.lucene.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.solr.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.lucene.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.solr.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cissues.solr.apache.org%3E

https://www.oracle.com/security-alerts/cpuoct2021.html

https://lists.apache.org/thread.html/[email protected]%3Cdev.ranger.apache.org%3E

https://www.oracle.com/security-alerts/cpujan2022.html

https://security.netapp.com/advisory/ntap-20220210-0002/

https://www.oracle.com/security-alerts/cpuapr2022.html

Details

Source: MITRE

Published: 2020-12-02

Updated: 2022-05-12

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Impact Score: 1.4

Exploitability Score: 3.9

Severity: MEDIUM