Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr7v-prvv-52v8

Опубликовано: 24 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

EPSS

Процентиль: 19%
0.0006
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-497

Связанные уязвимости

CVSS3: 6.8
ubuntu
4 месяца назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

CVSS3: 6.8
redhat
4 месяца назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

CVSS3: 6.8
nvd
4 месяца назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

CVSS3: 6.8
msrc
3 месяца назад

Описание отсутствует

CVSS3: 6.8
debian
4 месяца назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP re ...

EPSS

Процентиль: 19%
0.0006
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-497