7.5
CVE-2025-27820
- EPSS 0.33%
- Veröffentlicht 24.04.2025 11:44:25
- Zuletzt bearbeitet 16.07.2025 14:48:52
- Quelle security@apache.org
- CVE-Watchlists
- Unerledigt
Apache HttpComponents: PSL (Public Suffix List) validation bypass
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Httpclient Version >= 5.4 < 5.4.3
Netapp ≫ Ontap Tools Version10 SwPlatformvmware_vsphere
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.551 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.