CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
GoCNA
---
---
CISA-ADPADP
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVEADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bullseye
vulnerable
bookworm
no-dsa
golang-1.19
bookworm
vulnerable
bullseye
postponed
golang-1.23
sid
1.23.8-1
fixed
bookworm
no-dsa
bullseye
postponed
golang-1.24
sid
1.24.2-2
fixed
trixie
1.24.2-2
fixed
bookworm
no-dsa
bullseye
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne
golang-1.10
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
needs-triage
xenial
needs-triage
trusty
needs-triage
golang-1.13
plucky
dne
oracular
dne
noble
dne
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
dne
golang-1.14
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
needs-triage
bionic
dne
xenial
dne
trusty
dne
golang-1.16
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
needs-triage
bionic
needs-triage
xenial
dne
trusty
dne
golang-1.17
plucky
dne
oracular
dne
noble
dne
jammy
needs-triage
focal
dne
bionic
dne
xenial
dne
trusty
dne
golang-1.18
plucky
dne
oracular
dne
noble
dne
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
dne
golang-1.19
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne
golang-1.20
plucky
dne
oracular
dne
noble
dne
jammy
needs-triage
focal
needs-triage
bionic
dne
xenial
dne
trusty
dne
golang-1.21
plucky
dne
oracular
dne
noble
needs-triage
jammy
needs-triage
focal
needs-triage
bionic
dne
xenial
dne
trusty
dne
golang-1.22
plucky
dne
oracular
needs-triage
noble
needs-triage
jammy
needs-triage
focal
needs-triage
golang-1.23
plucky
not-affected
oracular
needs-triage
noble
needs-triage
jammy
needs-triage
focal
dne
golang-1.24
plucky
needs-triage
oracular
dne
noble
dne
jammy
dne
focal
dne
golang-1.6
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
dne
xenial
needs-triage
trusty
dne
golang-1.8
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
needs-triage
xenial
dne
trusty
dne
golang-1.9
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
needs-triage
xenial
dne
trusty
dne