httpclient5 is vulnerable to Missing Critical Step in Authentication
75
High Risk
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification.
You are affected if you are using a version that falls within the vulnerable range.
httpclient5 is vulnerable to Missing Critical Step in Authentication in versions 5.6 - 5.6.
Upgrade the org.apache.httpcomponents.client5:httpclient5 library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant