Metrics
Affected Vendors & Products
Fri, 14 Mar 2025 03:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat openshift Distributed Tracing |
|
CPEs | cpe:/a:redhat:openshift_distributed_tracing:3.5::el8 | |
Vendors & Products |
Redhat
Redhat openshift Distributed Tracing |
Fri, 21 Feb 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 28 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
ssvc
|
Tue, 28 Jan 2025 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2. |
Title | golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect | Sensitive headers incorrectly sent after cross-domain redirect in net/http |
References |
|
Fri, 24 Jan 2025 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | |
Title | golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: Go
Published: 2025-01-28T01:03:24.869Z
Updated: 2025-02-21T18:03:31.299Z
Reserved: 2024-08-27T19:41:58.555Z
Link: CVE-2024-45336

Updated: 2025-02-21T18:03:31.299Z

Status : Awaiting Analysis
Published: 2025-01-28T02:15:28.807
Modified: 2025-02-21T18:15:17.400
Link: CVE-2024-45336
