Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27558
HistoryOct 12, 2020 - 4:02 a.m.

Validation Bypass

2020-10-1204:02:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
28
httpclient
validation bypass
request execution
wrong target host
software vulnerability

EPSS

0.002

Percentile

53.0%

httpclient is vulnerable to validation bypass. A malformed authority component in the request URIs that is passed to the library as java.net.URI object would result in the request execution for a wrong target host.

References