CVE-2025-27820

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
Configurations

No configuration.

History

24 Apr 2025, 15:15

Type Values Removed Values Added
Summary
  • (es) Un error en la lógica de validación de PSL en Apache HttpClient 5.4.x deshabilita las comprobaciones de dominio, lo que afecta la gestión de cookies y la verificación del nombre de host. Descubierto por el equipo de Apache HttpClient. Corregido en la versión 5.4.3.
CWE CWE-295
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

24 Apr 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-24 12:15

Updated : 2025-04-24 15:15


NVD link : CVE-2025-27820

Mitre link : CVE-2025-27820

CVE.ORG link : CVE-2025-27820


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation