CVE Vulnerabilities

CVE-2020-13956

Published: Dec 02, 2020 | Modified: Dec 01, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

Affected Software

NameVendorStart VersionEnd Version
HttpclientApache*4.5.13 (excluding)
HttpclientApache5.0.0 (including)5.0.3 (excluding)
Red Hat AMQ 7.9.0RedHathttpclient*
Red Hat build of Quarkus 1.7.6RedHathttpclient*
Red Hat Enterprise Linux 8RedHatmaven:3.6-8060020211119162118.5dbfe8be*
Red Hat Enterprise Linux 8RedHatmaven:3.5-8060020211117110044.c0229ad2*
Red Hat Fuse 7.12RedHat*
Red Hat Fuse 7.9RedHathttpclient*
Red Hat Integration - Camel K - Tech-Preview 3RedHathttpclient*
Red Hat JBoss Enterprise Application Platform 7RedHathttpclient*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-activemq-artemis-0:2.9.0-7.redhat_00017.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-glassfish-jsf-0:2.3.9-12.SP13_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-hal-console-0:3.2.12-1.Final_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-hibernate-0:5.3.20-1.Final_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-httpcomponents-client-0:4.5.13-1.redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-jboss-ejb-client-0:4.0.37-1.Final_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-jboss-genericjms-0:2.0.8-1.Final_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-jboss-modules-0:1.11.0-1.Final_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-jboss-remoting-0:5.0.20-1.Final_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-jboss-server-migration-0:1.7.2-4.Final_redhat_00005.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-jboss-xnio-base-0:3.7.12-1.Final_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-narayana-0:5.9.10-1.Final_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-opentracing-interceptors-0:0.0.4.1-2.redhat_00002.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-resteasy-0:3.11.3-1.Final_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-undertow-0:2.0.33-1.SP2_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-wildfly-0:7.3.5-2.GA_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-wildfly-discovery-0:1.2.1-1.Final_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-wildfly-elytron-0:1.10.10-1.Final_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6RedHateap7-wildfly-http-client-0:1.0.24-1.Final_redhat_00001.1.el6eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-activemq-artemis-0:2.9.0-7.redhat_00017.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-glassfish-jsf-0:2.3.9-12.SP13_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-hal-console-0:3.2.12-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-hibernate-0:5.3.20-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-httpcomponents-client-0:4.5.13-1.redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-jboss-ejb-client-0:4.0.37-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-jboss-genericjms-0:2.0.8-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-jboss-modules-0:1.11.0-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-jboss-remoting-0:5.0.20-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-jboss-server-migration-0:1.7.2-4.Final_redhat_00005.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-jboss-xnio-base-0:3.7.12-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-narayana-0:5.9.10-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-opentracing-interceptors-0:0.0.4.1-2.redhat_00002.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-resteasy-0:3.11.3-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-undertow-0:2.0.33-1.SP2_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-wildfly-0:7.3.5-2.GA_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-wildfly-discovery-0:1.2.1-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-wildfly-elytron-0:1.10.10-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7RedHateap7-wildfly-http-client-0:1.0.24-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-activemq-artemis-0:2.9.0-7.redhat_00017.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-glassfish-jsf-0:2.3.9-12.SP13_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-hal-console-0:3.2.12-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-hibernate-0:5.3.20-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-httpcomponents-client-0:4.5.13-1.redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-jboss-ejb-client-0:4.0.37-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-jboss-genericjms-0:2.0.8-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-jboss-modules-0:1.11.0-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-jboss-remoting-0:5.0.20-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-jboss-server-migration-0:1.7.2-4.Final_redhat_00005.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-jboss-xnio-base-0:3.7.12-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-narayana-0:5.9.10-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-opentracing-interceptors-0:0.0.4.1-2.redhat_00002.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-resteasy-0:3.11.3-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-undertow-0:2.0.33-1.SP2_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-wildfly-0:7.3.5-2.GA_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-wildfly-discovery-0:1.2.1-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-wildfly-elytron-0:1.10.10-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8RedHateap7-wildfly-http-client-0:1.0.24-1.Final_redhat_00001.1.el8eap*
Red Hat Single Sign-On 7.4.5RedHathttpclient*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-maven36-httpcomponents-client-0:4.5.9-1.3.el7*
RHDM 7.10.0RedHathttpclient*
RHINT Service Registry 2.0.2 GARedHathttpclient*
RHPAM 7.10.1RedHathttpclient*
Httpcomponents-clientUbuntubionic*
Httpcomponents-clientUbuntuesm-apps/bionic*
Httpcomponents-clientUbuntuesm-apps/focal*
Httpcomponents-clientUbuntuesm-apps/xenial*
Httpcomponents-clientUbuntuesm-infra-legacy/trusty*
Httpcomponents-clientUbuntufocal*
Httpcomponents-clientUbuntugroovy*
Httpcomponents-clientUbuntutrusty*
Httpcomponents-clientUbuntutrusty/esm*
Httpcomponents-clientUbuntuupstream*
Httpcomponents-clientUbuntuxenial*

References