CVE-2011-1498
07.07.2011, 21:55
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.Enginsight
Vendor | Product | Version |
---|---|---|
apache | httpclient | 4.0 |
apache | httpclient | 4.0:alpha1 |
apache | httpclient | 4.0:alpha2 |
apache | httpclient | 4.0:alpha3 |
apache | httpclient | 4.0:alpha4 |
apache | httpclient | 4.0:beta1 |
apache | httpclient | 4.0:beta2 |
apache | httpclient | 4.0.1 |
apache | httpclient | 4.1 |
apache | httpclient | 4.1:alpha1 |
apache | httpclient | 4.1:alpha2 |
apache | httpclient | 4.1:beta1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References