Updated httpcomponents-client packages fix a security vulnerability
Publication date: 06 Jul 2021Modification date: 06 Jul 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-13956
Description
Priyank Nigam discovered that HttpComponents Client could misinterpret malformed authority component in a request URI and pick the wrong target host for request execution (CVE-2020-13956).
References
SRPMS
7/core
- httpcomponents-client-4.5.5-1.1.mga7