CVE-2011-1498
 
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
Apache HttpClient v4.x antes de v4.1.1 en Apache HttpComponents, cuando se utiliza con un servidor proxy de autenticación, envía el encabezado Proxy-Authorization al servidor de origen, lo que permite obtener información sensible a los servidores Web remotos mediante la comprobación de esta cabecera.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2011-03-21 CVE Reserved
- 2011-07-07 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=httpclient-users&m=129853896315461&w=2 | Mailing List | |
http://marc.info/?l=httpclient-users&m=129856318011586&w=2 | Mailing List | |
http://marc.info/?l=httpclient-users&m=129857589129183&w=2 | Mailing List | |
http://marc.info/?l=httpclient-users&m=129858274406594&w=2 | Mailing List | |
http://marc.info/?l=httpclient-users&m=129858299106950&w=2 | Mailing List | |
http://openwall.com/lists/oss-security/2011/04/07/7 | Mailing List | |
http://openwall.com/lists/oss-security/2011/04/08/1 | Mailing List | |
http://securityreason.com/securityalert/8298 | Third Party Advisory | |
http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.1.x.txt | X_refsource_confirm | |
http://www.kb.cert.org/vuls/id/153049 | Third Party Advisory | |
http://www.securityfocus.com/bid/46974 | Vdb Entry | |
https://bugzilla.redhat.com/show_bug.cgi?id=709531 | X_refsource_confirm | |
https://issues.apache.org/jira/browse/HTTPCLIENT-1061 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061440.html | 2011-09-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Httpclient Search vendor "Apache" for product "Httpclient" | 4.0 Search vendor "Apache" for product "Httpclient" and version "4.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Httpclient Search vendor "Apache" for product "Httpclient" | 4.0 Search vendor "Apache" for product "Httpclient" and version "4.0" | alpha1 |
Affected
| ||||||
Apache Search vendor "Apache" | Httpclient Search vendor "Apache" for product "Httpclient" | 4.0 Search vendor "Apache" for product "Httpclient" and version "4.0" | alpha2 |
Affected
| ||||||
Apache Search vendor "Apache" | Httpclient Search vendor "Apache" for product "Httpclient" | 4.0 Search vendor "Apache" for product "Httpclient" and version "4.0" | alpha3 |
Affected
| ||||||
Apache Search vendor "Apache" | Httpclient Search vendor "Apache" for product "Httpclient" | 4.0 Search vendor "Apache" for product "Httpclient" and version "4.0" | alpha4 |
Affected
| ||||||
Apache Search vendor "Apache" | Httpclient Search vendor "Apache" for product "Httpclient" | 4.0 Search vendor "Apache" for product "Httpclient" and version "4.0" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Httpclient Search vendor "Apache" for product "Httpclient" | 4.0 Search vendor "Apache" for product "Httpclient" and version "4.0" | beta2 |
Affected
| ||||||
Apache Search vendor "Apache" | Httpclient Search vendor "Apache" for product "Httpclient" | 4.0.1 Search vendor "Apache" for product "Httpclient" and version "4.0.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Httpclient Search vendor "Apache" for product "Httpclient" | 4.1 Search vendor "Apache" for product "Httpclient" and version "4.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Httpclient Search vendor "Apache" for product "Httpclient" | 4.1 Search vendor "Apache" for product "Httpclient" and version "4.1" | alpha1 |
Affected
| ||||||
Apache Search vendor "Apache" | Httpclient Search vendor "Apache" for product "Httpclient" | 4.1 Search vendor "Apache" for product "Httpclient" and version "4.1" | alpha2 |
Affected
| ||||||
Apache Search vendor "Apache" | Httpclient Search vendor "Apache" for product "Httpclient" | 4.1 Search vendor "Apache" for product "Httpclient" and version "4.1" | beta1 |
Affected
|