Advisories ยป MGASA-2021-0314

Updated httpcomponents-client packages fix a security vulnerability

Publication date: 06 Jul 2021
Modification date: 06 Jul 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-13956

Description

Priyank Nigam discovered that HttpComponents Client could misinterpret
malformed authority component in a request URI and pick the wrong target host
for request execution (CVE-2020-13956).
                

References

SRPMS

7/core