ALAS2-2023-1946


Amazon Linux 2 Security Advisory: ALAS-2023-1946
Advisory Release Date: 2023-02-17 00:11 Pacific
Advisory Updated Date: 2023-02-22 01:55 Pacific
Severity: Medium

Issue Overview:

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. (CVE-2020-13956)


Affected Packages:

httpcomponents-client


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update httpcomponents-client to update your system.

New Packages:
noarch:
    httpcomponents-client-4.2.5-5.amzn2.0.1.noarch
    httpcomponents-client-javadoc-4.2.5-5.amzn2.0.1.noarch

src:
    httpcomponents-client-4.2.5-5.amzn2.0.1.src