Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12547

Опубликовано: 25 апр. 2026
Источник: redhat
CVSS3: 3.4

Описание

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

Отчет

This vulnerability is deemed LOW because it requires the user changing the desktop proxy settings from an authenticated proxy to the attacker's proxy.

Меры по смягчению последствий

If changing desktop proxy settings, close any applications using libsoup, then restart the application after the setting has been changed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsoup3Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2489994libsoup: Information disclosure in libsoup via SoupAuthManager proxy credential leak on proxy switch

3.4 Low

CVSS3

Связанные уязвимости

CVSS3: 3.4
ubuntu
23 дня назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

CVSS3: 3.4
nvd
23 дня назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

msrc
17 дней назад

Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch

CVSS3: 3.4
debian
23 дня назад

SoupAuthManager caches proxy authentication credentials without scopin ...

CVSS3: 3.4
github
23 дня назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

3.4 Low

CVSS3