CVE-2011-1498
published 2011-07-07CVE-2011-1498: Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
6.69%
93.2th percentile
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | httpclient | — | — |
| apache | httpclient | — | — |
| apache | httpclient | — | — |
| debian | httpcomponents-client | < httpcomponents-client 4.1.1-1 (bookworm) | httpcomponents-client 4.1.1-1 (bookworm) |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClient
ghsa·2022-05-17
CVE-2011-1498 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClient
Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClient
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClient
osv·2022-05-17
CVE-2011-1498 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClient
Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClient
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
OSV
CVE-2011-1498: Apache HttpClient 4
osv·2011-07-07·CVSS 4.3
CVE-2011-1498 [MEDIUM] CVE-2011-1498: Apache HttpClient 4
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
Debian
CVE-2011-1498: httpcomponents-client - Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an a...
vendor_debian·2011·CVSS 4.3
CVE-2011-1498 [MEDIUM] CVE-2011-1498: httpcomponents-client - Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an a...
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
Scope: local
bookworm: resolved (fixed in 4.1.1-1)
bullseye: resolved (fixed in 4.1.1-1)
forky: resolved (fixed in 4.1.1-1)
sid: resolved (fixed in 4.1.1-1)
trixie: resolved (fixed in 4.1.1-1)
No detection rules found.
No public exploits indexed.
arXiv
Impact assessment for vulnerabilities in open-source software libraries
arxiv_fulltext·2015-04-21
Impact assessment for vulnerabilities in open-source software libraries
fancy
Software applications integrate more and more open-source software
(OSS) to benefit from code reuse. As a drawback, each vulnerability
discovered in bundled OSS potentially affects the application. Upon
the disclosure of every new vulnerability, the application vendor has
to decide whether it is exploitable in his particular usage context,
hence, whether users require an urgent application patch containing a
non-vulnerable version of the OSS. Current decision making is mostly
based on high-level vulnerability descriptions and expert knowledge,
thus, effort intense and error prone. This paper proposes a pragmatic
approach to facilitate the impact assessment, describes a
proof-of-concept for Java, and examines one example vulnerability as
case study. The approach is independent from s
Bugzilla
CVE-2011-4320 ejabberd (mod_pubsub): DoS (infinite loop, excessive CPU consumption) by processing malformed <publish> stanza
bugzilla·2011-11-21·CVSS 4.0
CVE-2011-4320 [MEDIUM] CVE-2011-4320 ejabberd (mod_pubsub): DoS (infinite loop, excessive CPU consumption) by processing malformed <publish> stanza
CVE-2011-4320 ejabberd (mod_pubsub): DoS (infinite loop, excessive CPU consumption) by processing malformed stanza
A denial of service flaw was found in the way PubSub extension of the ejabberd, a distributed, fault-tolerant Jabber/XMPP server, performed processing of certain, malformed stanzas. A remote attacker, authenticated Jabber user, could send a specially-crafted request to Jabber server, leading to the jabberd daemon to enter an infinite loop and consume excessive amount of CPU, while processing the stanza.
References:
[1] http://www.ejabberd.im/ejabberd-2.1.9
Upstream bug report:
[2] https://support.process-one.net/browse/EJAB-1498
Relevant upstream commits:
[3] https://git.process-one.net/ejabberd/mainline/commit/d3c4eab46f3cd54f7686cfed740d9c130b6801cf
(original fix to corr
Bugzilla
CVE-2011-1498 httpcomponents-client: sends Proxy-Authorization header to host when tunneling requests through authenticated proxy server
bugzilla·2011-05-31·CVSS 4.3
CVE-2011-1498 [MEDIUM] CVE-2011-1498 httpcomponents-client: sends Proxy-Authorization header to host when tunneling requests through authenticated proxy server
CVE-2011-1498 httpcomponents-client: sends Proxy-Authorization header to host when tunneling requests through authenticated proxy server
From the httpclient release notes for version 4.1.1 [1]:
[HTTPCLIENT-1061] Fixed critical bug causing Proxy-Authorization header to be
sent to the target host when tunneling requests through a proxy server that
requires authentication.
[1] http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.1.x.txt
Discussion:
Created httpcomponents-client tracking bugs for this issue
Affects: fedora-15 [bug 709532]
---
FC16 has 4.1.2, F17 has 4.1.3, and this is fixed in upstream 4.1.1 release.
Bugzilla
CVE-2011-1498 httpcomponents-client: sends Proxy-Authorization header to host when tunneling requests through authenticated proxy server [fedora-15]
bugzilla·2011-05-31·CVSS 4.3
CVE-2011-1498 [MEDIUM] CVE-2011-1498 httpcomponents-client: sends Proxy-Authorization header to host when tunneling requests through authenticated proxy server [fedora-15]
CVE-2011-1498 httpcomponents-client: sends Proxy-Authorization header to host when tunneling requests through authenticated proxy server [fedora-15]
fedora-15 tracking bug for httpcomponents-client: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
This message is a notice that Fedora 15 is now at end of life. Fedora
has stopped maintaining and issuing updates for Fedora 15. It is
Fedora's policy to close all bug reports from releases that are no
longer maintained. At this time, all open bugs with a Fedora 'version'
of '15' have been closed as WONTFIX.
(Please note: Our normal process is to give advanced warning of
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061440.htmlhttp://marc.info/?l=httpclient-users&m=129853896315461&w=2http://marc.info/?l=httpclient-users&m=129856318011586&w=2http://marc.info/?l=httpclient-users&m=129857589129183&w=2http://marc.info/?l=httpclient-users&m=129858274406594&w=2http://marc.info/?l=httpclient-users&m=129858299106950&w=2http://openwall.com/lists/oss-security/2011/04/07/7http://openwall.com/lists/oss-security/2011/04/08/1http://securityreason.com/securityalert/8298http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.1.x.txthttp://www.kb.cert.org/vuls/id/153049http://www.securityfocus.com/bid/46974https://bugzilla.redhat.com/show_bug.cgi?id=709531https://issues.apache.org/jira/browse/HTTPCLIENT-1061http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061440.htmlhttp://marc.info/?l=httpclient-users&m=129853896315461&w=2http://marc.info/?l=httpclient-users&m=129856318011586&w=2http://marc.info/?l=httpclient-users&m=129857589129183&w=2http://marc.info/?l=httpclient-users&m=129858274406594&w=2http://marc.info/?l=httpclient-users&m=129858299106950&w=2http://openwall.com/lists/oss-security/2011/04/07/7http://openwall.com/lists/oss-security/2011/04/08/1http://securityreason.com/securityalert/8298http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.1.x.txthttp://www.kb.cert.org/vuls/id/153049http://www.securityfocus.com/bid/46974https://bugzilla.redhat.com/show_bug.cgi?id=709531https://issues.apache.org/jira/browse/HTTPCLIENT-1061
2011-07-07
Published