Skip to content

[deps]: Update org.apache.httpcomponents.client5:httpclient5 to v5.4.3 [SECURITY]#121

Merged
mandreko-bitwarden merged 1 commit into
mainfrom
renovate/maven-org.apache.httpcomponents.client5-httpclient5-vulnerability
Jul 25, 2025
Merged

[deps]: Update org.apache.httpcomponents.client5:httpclient5 to v5.4.3 [SECURITY]#121
mandreko-bitwarden merged 1 commit into
mainfrom
renovate/maven-org.apache.httpcomponents.client5-httpclient5-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Apr 24, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
org.apache.httpcomponents.client5:httpclient5 5.4.1 -> 5.4.3 age confidence

GitHub Vulnerability Alerts

CVE-2025-27820

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from a team as a code owner April 24, 2025 18:37
@renovate renovate Bot added the security label Apr 24, 2025
@github-actions

github-actions Bot commented May 2, 2025

Copy link
Copy Markdown

Logo
Checkmarx One – Scan Summary & Detailsd87406e2-ad22-42f2-b919-3f5957c6cb92

New Issues (1)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2025-22235 Maven-org.springframework.boot:spring-boot-3.1.3
detailsDescription: `EndpointRequest.to()` creates a matcher for `null/**` if the actuator endpoint, for which the `EndpointRequest` has been created, is disabled or n...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: K54uK0Hn4lfdaOqLXvX%2B37Jr1mTl%2B67TdCczewtUjr4%3D
Vulnerable Package
Fixed Issues (1)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
HIGH CVE-2025-27820 Maven-org.apache.httpcomponents.client5:httpclient5-5.4.1

@mandreko-bitwarden mandreko-bitwarden merged commit dc5ae86 into main Jul 25, 2025
3 checks passed
@mandreko-bitwarden mandreko-bitwarden deleted the renovate/maven-org.apache.httpcomponents.client5-httpclient5-vulnerability branch July 25, 2025 20:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants