Описание
Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| azl3 libsoup 3.4.4-16 on Azure Linux 3.0 | ||
| cbl2 libsoup 3.0.4-13 on CBL-Mariner 2.0 |
Показывать по
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
A flaw was found in libsoup. When establishing HTTPS tunnels through a ...
EPSS
5.9 Medium
CVSS3