CVE-2024-45336

Source
https://cve.org/CVERecord?id=CVE-2024-45336
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45336.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-45336
Aliases
Downstream
AZL (5)
BELL (1)
CGA (1719)
CLEANSTART (6)
CLSA (1)
DEBIAN (1)
ECHO (1)
MGASA (1)
MINI (18)
OESA (4)
openSUSE (5)
RHSA (13)
RLSA (5)
SUSE (8)
UBUNTU (1)
Related
Published
2025-01-28T02:15:28Z
Modified
2026-09-10T11:26:38Z
Summary
[none]
Details

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

References

Affected packages