Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gmf9-8jmv-v2q8

Опубликовано: 21 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.4

Описание

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

EPSS

Процентиль: 14%
0.00228
Низкий

3.4 Low

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 3.4
ubuntu
23 дня назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

CVSS3: 3.4
redhat
4 месяца назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

CVSS3: 3.4
nvd
23 дня назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

msrc
17 дней назад

Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch

CVSS3: 3.4
debian
23 дня назад

SoupAuthManager caches proxy authentication credentials without scopin ...

EPSS

Процентиль: 14%
0.00228
Низкий

3.4 Low

CVSS3

Дефекты

CWE-201