4.3
CVSSv2

CVE-2011-1498

Published: 07/07/2011 Updated: 22/09/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Apache HttpClient 4.x prior to 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache httpclient 4.0

apache httpclient 4.1

apache httpclient 4.0.1

Vendor Advisories

Debian Bug report logs - #628727 httpcomponents-client security issue CVE-2011-1498 Package: httpcomponents-client; Maintainer for httpcomponents-client is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Thijs Kinkhorst <thijs@debianorg> Date: Tue, 31 May 2011 19:21:01 UTC Severi ...