Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-4673

Опубликовано: 11 июн. 2025
Источник: redhat
CVSS3: 6.8

Описание

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2openshift-golang-builder-containerUnder investigation
Red Hat Enterprise Linux 10golangUnder investigation
Red Hat Enterprise Linux 8go-toolset:rhel8/golangUnder investigation
Red Hat Enterprise Linux 8go-toolset:rhel8/go-toolsetUnder investigation
Red Hat Enterprise Linux 9golangUnder investigation
Red Hat Enterprise Linux AI (RHEL AI)golangUnder investigation
Red Hat OpenShift Container Platform 4openshift-golang-builder-containerUnder investigation
Red Hat OpenShift Virtualization 4openshift-golang-builder-containerUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2373305net/http: Sensitive headers not cleared on cross-origin redirect in net/http

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
9 дней назад

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

CVSS3: 6.8
nvd
9 дней назад

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

CVSS3: 6.8
debian
9 дней назад

Proxy-Authorization and Proxy-Authenticate headers persisted on cross- ...

CVSS3: 6.8
github
9 дней назад

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

suse-cvrf
11 дней назад

Security update for go1.23

6.8 Medium

CVSS3

Уязвимость CVE-2025-4673