CVE-2025-27820

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*

History

16 Jul 2025, 14:48

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250516-0003/ - Third Party Advisory
References () https://github.com/apache/httpcomponents-client/pull/574 - () https://github.com/apache/httpcomponents-client/pull/574 - Issue Tracking, Patch
References () https://github.com/apache/httpcomponents-client/pull/621 - () https://github.com/apache/httpcomponents-client/pull/621 - Issue Tracking, Patch
References () https://hc.apache.org/httpcomponents-client-5.4.x/index.html - () https://hc.apache.org/httpcomponents-client-5.4.x/index.html - Product
References () https://lists.apache.org/thread/55xhs40ncqv97qvoocok44995xp5kqn8 - () https://lists.apache.org/thread/55xhs40ncqv97qvoocok44995xp5kqn8 - Mailing List, Patch
CPE cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*
First Time Apache
Netapp ontap Tools
Apache httpclient
Netapp

24 Apr 2025, 15:15

Type Values Removed Values Added
CWE CWE-295
Summary
  • (es) Un error en la lógica de validación de PSL en Apache HttpClient 5.4.x deshabilita las comprobaciones de dominio, lo que afecta la gestión de cookies y la verificación del nombre de host. Descubierto por el equipo de Apache HttpClient. Corregido en la versión 5.4.3.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

24 Apr 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-24 12:15

Updated : 2025-07-16 14:48


NVD link : CVE-2025-27820

Mitre link : CVE-2025-27820

CVE.ORG link : CVE-2025-27820


JSON object : View

Products Affected

netapp

  • ontap_tools

apache

  • httpclient
CWE
CWE-295

Improper Certificate Validation