Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-46421

Опубликовано: 24 апр. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.8

Описание

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

РелизСтатусПримечание
devel

released

2.74.3-10.1ubuntu1
esm-apps/resolute

released

2.74.3-10.1ubuntu1
esm-infra-legacy/xenial

released

2.52.2-1ubuntu0.3+esm1
esm-infra/bionic

released

2.62.1-1ubuntu0.4+esm2
esm-infra/focal

released

2.70.0-1ubuntu0.3
esm-infra/xenial

released

2.52.2-1ubuntu0.3+esm1
focal

released

2.70.0-1ubuntu0.3
jammy

released

2.74.2-3ubuntu0.3
noble

released

2.74.3-6ubuntu1.3
oracular

released

2.74.3-7ubuntu0.3

Показывать по

РелизСтатусПримечание
devel

not-affected

3.6.5-1
esm-apps/jammy

released

3.0.7-0ubuntu1+esm3
esm-infra/focal

DNE

focal

DNE

jammy

needed

noble

released

3.4.4-5ubuntu0.3
oracular

released

3.6.0-2ubuntu0.3
plucky

not-affected

3.6.5-1
questing

not-affected

3.6.5-1
resolute

not-affected

3.6.5-1

Показывать по

EPSS

Процентиль: 43%
0.00545
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
redhat
больше 1 года назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

CVSS3: 6.8
nvd
больше 1 года назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

CVSS3: 6.8
msrc
около 1 года назад

Libsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a server

CVSS3: 6.8
debian
больше 1 года назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP re ...

CVSS3: 6.8
github
больше 1 года назад

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

EPSS

Процентиль: 43%
0.00545
Низкий

6.8 Medium

CVSS3