Amazon Linux 2 Security Advisory: ALAS-2023-1946
Advisory Release Date: 2023-02-17 00:11 Pacific
Advisory Updated Date: 2023-02-22 01:55 Pacific
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. (CVE-2020-13956)
Affected Packages:
httpcomponents-client
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update httpcomponents-client to update your system.
noarch:
httpcomponents-client-4.2.5-5.amzn2.0.1.noarch
httpcomponents-client-javadoc-4.2.5-5.amzn2.0.1.noarch
src:
httpcomponents-client-4.2.5-5.amzn2.0.1.src