CVE-2011-1498

Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
VendorProductVersion
apachehttpclient
4.0
apachehttpclient
4.0:alpha1
apachehttpclient
4.0:alpha2
apachehttpclient
4.0:alpha3
apachehttpclient
4.0:alpha4
apachehttpclient
4.0:beta1
apachehttpclient
4.0:beta2
apachehttpclient
4.0.1
apachehttpclient
4.1
apachehttpclient
4.1:alpha1
apachehttpclient
4.1:alpha2
apachehttpclient
4.1:beta1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
httpcomponents-client
bullseye
4.5.13-2
fixed
bookworm
4.5.14-1
fixed
sid
4.5.14-1
fixed
trixie
4.5.14-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
httpcomponents-client
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
ignored
maverick
ignored
lucid
dne
hardy
dne
References