Описание
Security update for perl-libwww-perl
This update for perl-libwww-perl fixes the following issue
- CVE-2026-8368: LWP: UserAgent: Authorization and Proxy-Authorization headers are leaked on cross-origin redirects (bsc#1265156).
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP7
perl-libwww-perl-6.31-150000.3.3.1
Ссылки
- Link for SUSE-SU-2026:2962-1
- E-Mail link for SUSE-SU-2026:2962-1
- SUSE Security Ratings
- SUSE Bug 1265156
- SUSE CVE CVE-2026-8368 page
Описание
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes. A redirect to an attacker controlled host therefore discloses the caller's credentials to that host.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:perl-libwww-perl-6.31-150000.3.3.1
Ссылки
- CVE-2026-8368
- SUSE Bug 1265156