Priyank Nigam discovered that HttpComponents Client could misinterpret
malformed authority component in a request URI and pick the wrong target host
for request execution (CVE-2020-13956).
- https://bugs.mageia.org/show_bug.cgi?id=27389
- https://lists.debian.org/debian-security-announce/2020/msg00179.html
- https://www.cve.org/CVERecord?id=CVE-2020-13956
- 7/core/httpcomponents-client-4.5.5-1.1.mga7
Get the latest Linux and open source security news straight to your inbox.