When encountering an HTTP redirect, libsoup clients prior to version 3.6.5 send the HTTP Authorization header to the host that is the target of the redirection, allowing this host to impersonate the user to the host that performed the redirect.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:4439 https://access.redhat.com/errata/RHSA-2025:4439
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:4440 https://access.redhat.com/errata/RHSA-2025:4440
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2025:4508 https://access.redhat.com/errata/RHSA-2025:4508
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:4538 https://access.redhat.com/errata/RHSA-2025:4538
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:4560 https://access.redhat.com/errata/RHSA-2025:4560
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2025:4568 https://access.redhat.com/errata/RHSA-2025:4568
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2025:4609 https://access.redhat.com/errata/RHSA-2025:4609
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:4624 https://access.redhat.com/errata/RHSA-2025:4624
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7436 https://access.redhat.com/errata/RHSA-2025:7436
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7505 https://access.redhat.com/errata/RHSA-2025:7505