Metrics
Affected Vendors & Products
Thu, 10 Apr 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:enterprise_linux:8 |
Fri, 04 Apr 2025 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat rhel Eus
|
|
CPEs | cpe:/a:redhat:rhel_eus:9.4 | |
Vendors & Products |
Redhat rhel Eus
|
Fri, 28 Mar 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat enterprise Linux
|
|
CPEs | cpe:/a:redhat:enterprise_linux:9 | |
Vendors & Products |
Redhat enterprise Linux
|
Thu, 27 Mar 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat logging
|
|
CPEs | cpe:/a:redhat:logging:6.1::el9 | |
Vendors & Products |
Redhat logging
|
Fri, 14 Mar 2025 03:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat openshift Distributed Tracing |
|
CPEs | cpe:/a:redhat:openshift_distributed_tracing:3.5::el8 | |
Vendors & Products |
Redhat
Redhat openshift Distributed Tracing |
Fri, 21 Feb 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 28 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
ssvc
|
Tue, 28 Jan 2025 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2. |
Title | golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect | Sensitive headers incorrectly sent after cross-domain redirect in net/http |
References |
|
Fri, 24 Jan 2025 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | |
Title | golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-02-21T18:03:31.299Z
Reserved: 2024-08-27T19:41:58.555Z
Link: CVE-2024-45336

Updated: 2025-02-21T18:03:31.299Z

Status : Awaiting Analysis
Published: 2025-01-28T02:15:28.807
Modified: 2025-02-21T18:15:17.400
Link: CVE-2024-45336
