Apache HttpClient
cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*
- >= 5.4.0, < 5.4.3
A vulnerability exists in Apache HttpClient versions 5.4.0 prior to 5.4.3, where a bug in the Public Suffix List (PSL) validation logic disables essential domain checks. This flaw affects cookie management and host name verification, potentially leading to unauthorized access or information disclosure. The issue was discovered by the Apache HttpClient team and is fixed in version 5.4.3.
Exploitation of this vulnerability bypasses Public Suffix List validation, disrupting cookie management and host name verification. This could result in unauthorized access or information disclosure.
Users are advised to upgrade to Apache HttpClient version 5.4.3, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.