Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LApache Httpclient
APPApache5.6
Powiązane podatności
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerific...
Apache HttpClient 4.3.x — brak weryfikacji X509HostnameVerifier (null pointer)
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management a...
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the con...
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in...