Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr7v-prvv-52v8

Опубликовано: 24 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

EPSS

Процентиль: 16%
0.00052
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-497

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 2 месяцев назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

CVSS3: 6.8
redhat
около 2 месяцев назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

CVSS3: 6.8
nvd
около 2 месяцев назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

CVSS3: 6.8
msrc
около 1 месяца назад

Описание отсутствует

CVSS3: 6.8
debian
около 2 месяцев назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP re ...

EPSS

Процентиль: 16%
0.00052
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-497