Описание
Security update for perl-libwww-perl
This update for perl-libwww-perl fixes the following issue
- CVE-2026-8368: authorization and proxy-authorization headers are leaked on cross-origin redirects (bsc#1265156).
Список пакетов
openSUSE Leap 16.0
perl-libwww-perl-6.770.0-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1265156
- SUSE CVE CVE-2026-8368 page
Описание
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes. A redirect to an attacker controlled host therefore discloses the caller's credentials to that host.
Затронутые продукты
openSUSE Leap 16.0:perl-libwww-perl-6.770.0-160000.3.1
Ссылки
- CVE-2026-8368
- SUSE Bug 1265156