Bug 2361962 (CVE-2025-46421)
Summary: | CVE-2025-46421 libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | Keywords: | Security |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | --- | |
Doc Text: |
A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2361966, 2361968, 2361969 | ||
Bug Blocks: |
Description
OSIDB Bzimport
2025-04-24 01:38:31 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:4439 https://access.redhat.com/errata/RHSA-2025:4439 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:4440 https://access.redhat.com/errata/RHSA-2025:4440 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2025:4508 https://access.redhat.com/errata/RHSA-2025:4508 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:4538 https://access.redhat.com/errata/RHSA-2025:4538 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:4560 https://access.redhat.com/errata/RHSA-2025:4560 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2025:4568 https://access.redhat.com/errata/RHSA-2025:4568 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2025:4609 https://access.redhat.com/errata/RHSA-2025:4609 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:4624 https://access.redhat.com/errata/RHSA-2025:4624 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7436 https://access.redhat.com/errata/RHSA-2025:7436 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7505 https://access.redhat.com/errata/RHSA-2025:7505 |