ARTICLE AD BOX
Published : Jan. 28, 2025, 2:15 a.m. | 16 minutes ago
Description : The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...