Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr7v-prvv-52v8

Опубликовано: 24 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

EPSS

Процентиль: 68%
0.00543
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-497

Связанные уязвимости

CVSS3: 6.8
ubuntu
11 месяцев назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

CVSS3: 6.8
redhat
11 месяцев назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

CVSS3: 6.8
nvd
11 месяцев назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

CVSS3: 6.8
msrc
11 месяцев назад

Libsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a server

CVSS3: 6.8
debian
11 месяцев назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP re ...

EPSS

Процентиль: 68%
0.00543
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-497