CVE
- Id
- 49410
- CVE No.
- CVE-2011-1498
- Status
- Candidate
- Description
- Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
- Phase
- Assigned (20110321)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
536331 | 49410 | CVE-2011-1498 | MLIST:[httpclient-users] 20110224 Proxy-Authorization header received on server side | View |
536332 | 49410 | CVE-2011-1498 | URL:http://marc.info/?l=httpclient-users&m=129853896315461&w=2 | View |
536333 | 49410 | CVE-2011-1498 | MLIST:[httpclient-users] 20110224 RE: Proxy-Authorization header received on server side | View |
536334 | 49410 | CVE-2011-1498 | URL:http://marc.info/?l=httpclient-users&m=129857589129183&w=2 | View |
536335 | 49410 | CVE-2011-1498 | MLIST:[httpclient-users] 20110224 RE: Proxy-Authorization header received on server side | View |
536336 | 49410 | CVE-2011-1498 | URL:http://marc.info/?l=httpclient-users&m=129858299106950&w=2 | View |
536337 | 49410 | CVE-2011-1498 | MLIST:[httpclient-users] 20110224 Re: Proxy-Authorization header received on server side | View |
536338 | 49410 | CVE-2011-1498 | URL:http://marc.info/?l=httpclient-users&m=129856318011586&w=2 | View |
536339 | 49410 | CVE-2011-1498 | MLIST:[httpclient-users] 20110224 Re: Proxy-Authorization header received on server side | View |
536340 | 49410 | CVE-2011-1498 | URL:http://marc.info/?l=httpclient-users&m=129858274406594&w=2 | View |
536341 | 49410 | CVE-2011-1498 | MLIST:[oss-security] 20110407 Apache HttpClient CVE request [VU#153049] | View |
536342 | 49410 | CVE-2011-1498 | URL:http://openwall.com/lists/oss-security/2011/04/07/7 | View |
536343 | 49410 | CVE-2011-1498 | MLIST:[oss-security] 20110408 Re: Apache HttpClient CVE request [VU#153049] | View |
536344 | 49410 | CVE-2011-1498 | URL:http://openwall.com/lists/oss-security/2011/04/08/1 | View |
536345 | 49410 | CVE-2011-1498 | CONFIRM:http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.1.x.txt | View |
536346 | 49410 | CVE-2011-1498 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=709531 | View |
536347 | 49410 | CVE-2011-1498 | CONFIRM:https://issues.apache.org/jira/browse/HTTPCLIENT-1061 | View |
536348 | 49410 | CVE-2011-1498 | FEDORA:FEDORA-2011-7747 | View |
536349 | 49410 | CVE-2011-1498 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061440.html | View |
536350 | 49410 | CVE-2011-1498 | CERT-VN:VU#153049 | View |
536351 | 49410 | CVE-2011-1498 | URL:http://www.kb.cert.org/vuls/id/153049 | View |
536352 | 49410 | CVE-2011-1498 | BID:46974 | View |
536353 | 49410 | CVE-2011-1498 | URL:http://www.securityfocus.com/bid/46974 | View |
536354 | 49410 | CVE-2011-1498 | SREASON:8298 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
37816 | JVNDB-2010-003601 | Liferay Portal CE の XSL Content portlet における任意の XSL および XML ファイルを読まれる脆弱性 | Liferay Portal Community Edition (CE) の XSL Content portlet には、Apache Tomcat または Oracle GlassFish を使用している際、任意の XSL および XML ファイルを読まれる脆弱性が存在します。 | CVE-2011-1503 | 49410 | 3.5 | http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-003601.html | View |