#VU47481 Input validation error in Apache HttpComponents - CVE-2020-13956
Published: October 9, 2020
Apache HttpComponents
Apache Foundation
Description
The vulnerability allows a remote attacker to compromise the affected application.
The vulnerability exists due to insufficient validation of user-supplied input in Apache HttpClient. A remote attacker can pass request URIs to the library as java.net.URI object and force the application to pick the wrong target host for request execution.