Описание
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.
Отчет
This vulnerability is deemed LOW because it requires the user changing the desktop proxy settings from an authenticated proxy to the attacker's proxy.
Меры по смягчению последствий
If changing desktop proxy settings, close any applications using libsoup, then restart the application after the setting has been changed.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libsoup3 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
3.4 Low
CVSS3
Связанные уязвимости
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.
Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch
SoupAuthManager caches proxy authentication credentials without scopin ...
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.
3.4 Low
CVSS3