CVE-2020-13956

MEDIUM

Apache HttpClient <4.5.13, 5.0.3 - SSRF

Title source: llm
STIX 2.1

Description

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

References (64)

Core 64
Core References
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuApr2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220210-0002/

Scores

CVSS v3 5.3
EPSS 0.0050
EPSS Percentile 66.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

Status published
Products (28)
apache/httpclient < 4.5.13
netapp/active_iq_unified_manager (3 CPE variants)
netapp/snapcenter
oracle/commerce_guided_search 11.3.2
oracle/communications_cloud_native_core_service_communication_proxy 1.14.0
oracle/data_integrator 12.2.1.3.0
oracle/data_integrator 12.2.1.4.0
oracle/jd_edwards_enterpriseone_orchestrator < 9.2.6.0
oracle/jd_edwards_enterpriseone_tools < 9.2.6.0
oracle/nosql_database < 20.3
... and 18 more
Published Dec 02, 2020
Tracked Since Feb 18, 2026