-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: rh-maven36-httpcomponents-client security update
Advisory ID:       RHSA-2022:0722-01
Product:           Red Hat Software Collections
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:0722
Issue date:        2022-03-01
CVE Names:         CVE-2020-13956 
====================================================================
1. Summary:

An update for rh-maven36-httpcomponents-client is now available for Red Hat
Software Collections.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch

3. Description:

HttpClient is a HTTP/1.1 compliant HTTP agent implementation based on
httpcomponents HttpCore. It also provides reusable components for
client-side authentication, HTTP state management, and HTTP connection
management.

Security Fix(es):

* apache-httpclient: incorrect handling of malformed authority component in
request URIs (CVE-2020-13956)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1886587 - CVE-2020-13956 apache-httpclient: incorrect handling of malformed authority component in request URIs

6. Package List:

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):

Source:
rh-maven36-httpcomponents-client-4.5.9-1.3.el7.src.rpm

noarch:
rh-maven36-httpcomponents-client-4.5.9-1.3.el7.noarch.rpm
rh-maven36-httpcomponents-client-javadoc-4.5.9-1.3.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):

Source:
rh-maven36-httpcomponents-client-4.5.9-1.3.el7.src.rpm

noarch:
rh-maven36-httpcomponents-client-4.5.9-1.3.el7.noarch.rpm
rh-maven36-httpcomponents-client-javadoc-4.5.9-1.3.el7.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-13956
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYh5GM9zjgjWX9erEAQi07hAAjGG6Xe5WtxaGuqYbjMNe3zvWfUCoPNVQ
u6Oad78XkTKikSPSSMSleUm4EFU1CYjU3azY3xiuhOchka+DAr9r784rXrBmxOqc
PG4iG7AkCmFsd3imrkjvWWtOsNzAGq04lZ9+0mJZL31T8Dea3pTEbamaAU2Lzbry
vf1k12YaNYjxCNlX7bit8+tygaK8yb0upUJIPapKsFl2y7ft1M4m6KoiyvWhNsqm
HPio7gCcb+cICNcP3PYkg7ze1HIVbnPdvsCrzaT42F1Zj3vmUD8cAt9GJuPzCVHq
OJY2JIG/KwHQuSMaK8a2S2lLsUwHDiD7eCsAVs5RSaIPtMo8ExXMTOIJwg6+oqWD
VS1eGpHxGv+hUSIAH39eyiSwYOKbWUVnhWyPqdblrEt7kZBeoNwi1eT1SH9j2IYY
Ew3TtW2CKPzk1SXo9qRnFdb3TRMs3FMmk44lvXru8X12KUEQqnnnAlco6LdVb9ri
SpO88wEN/BFXrx10HYj8k5gd8eFelDraqKHgIGvxm+31APB9H558IeH3AyS+83es
exfw5QlBfTdaBKJ74FKDwultL97zaAkR8tadhfC0YVCiGVyMVUV4n2bo+SR1f865
uesF7SZ1M3IDMIFGc/QsIupL53E15kCAD4pF39I9MGy+pMYOmXMMzk4IUJM8cSPn
PX5OYlIS1kc=5F1z
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2022-0722:01 Moderate: rh-maven36-httpcomponents-client

An update for rh-maven36-httpcomponents-client is now available for Red Hat Software Collections

Summary

HttpClient is a HTTP/1.1 compliant HTTP agent implementation based on httpcomponents HttpCore. It also provides reusable components for client-side authentication, HTTP state management, and HTTP connection management.
Security Fix(es):
* apache-httpclient: incorrect handling of malformed authority component in request URIs (CVE-2020-13956)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2020-13956 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-maven36-httpcomponents-client-4.5.9-1.3.el7.src.rpm
noarch: rh-maven36-httpcomponents-client-4.5.9-1.3.el7.noarch.rpm rh-maven36-httpcomponents-client-javadoc-4.5.9-1.3.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):
Source: rh-maven36-httpcomponents-client-4.5.9-1.3.el7.src.rpm
noarch: rh-maven36-httpcomponents-client-4.5.9-1.3.el7.noarch.rpm rh-maven36-httpcomponents-client-javadoc-4.5.9-1.3.el7.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2022:0722-01
Product: Red Hat Software Collections
Advisory URL: https://access.redhat.com/errata/RHSA-2022:0722
Issued Date: : 2022-03-01
CVE Names: CVE-2020-13956

Topic

An update for rh-maven36-httpcomponents-client is now available for Red HatSoftware Collections.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch


Bugs Fixed

1886587 - CVE-2020-13956 apache-httpclient: incorrect handling of malformed authority component in request URIs


Related News