Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-4673

Опубликовано: 11 июн. 2025
Источник: debian
EPSS Низкий

Описание

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.24fixed1.24.4-1package
golang-1.23fixed1.23.10-1package
golang-1.19removedpackage
golang-1.19no-dsabookwormpackage
golang-1.15removedpackage
golang-1.15postponedbullseyepackage

Примечания

  • https://github.com/golang/go/issues/73816

  • Fixed by: https://github.com/golang/go/commit/85897ca220a149333a88b1e4d63f3b751f1141f5 (go1.24.4)

  • Fixed by: https://github.com/golang/go/commit/b897e97c36cb62629a458bc681723ca733404e32 (go1.23.10)

EPSS

Процентиль: 12%
0.00044
Низкий

Связанные уязвимости

CVSS3: 6.8
ubuntu
2 месяца назад

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

CVSS3: 6.8
redhat
2 месяца назад

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

CVSS3: 6.8
nvd
2 месяца назад

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

CVSS3: 6.8
msrc
около 1 месяца назад

Описание отсутствует

CVSS3: 6.8
github
2 месяца назад

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

EPSS

Процентиль: 12%
0.00044
Низкий