← Back

CVE-2011-1498

nvd nist
Published: Jul 7, 2011Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.

Affected (12)

Products: Apache: Httpclient
1 product
Httpclient
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 4.0.1
Version 4.0
Version 4.0 alpha1
Version 4.0 alpha2
Version 4.0 alpha3
Version 4.0 alpha4
Version 4.0 beta1
Version 4.0 beta2
Version 4.1
Version 4.1 alpha1
Version 4.1 alpha2
Version 4.1 beta1

References (28)

Source: secalert@redhat.com
US Government Resource
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.