Apache HttpClient Vulnerability Exposes Sensitive Information via Proxy-Authorization Header
CVE-2011-1498

Currently unrated

Key Information:

Vendor
Apache
Vendor
CVE Published:
7 July 2011

Summary

The Apache HttpClient prior to version 4.1.1 contains a vulnerability that reveals sensitive information to remote web servers. When used in conjunction with an authenticating proxy server, the HttpClient incorrectly sends the Proxy-Authorization header to the origin server. This behavior could allow attackers on the web server to log and capture the Proxy-Authorization header, leading to potential exposure of credentials or other sensitive data. It is crucial for users of affected versions to update to the latest release to mitigate this issue.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.