CVE-2011-1498
Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClient
EPSS 6.7%
描述
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
如何修補 CVE-2011-1498
要修補 CVE-2011-1498,請將受影響套件升級到下列已修補版本。
- Debian/httpcomponents-client—升級至 4.1.1-1 或更新版本
- Maven/org.apache.httpcomponents:httpclient—升級至 4.1.1 或更新版本
CVE-2011-1498 正在被利用嗎?
中等 — EPSS 為 6.7%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 4.1.1-1
- >= 4.0.0, < 4.1.1