CVE-2024-45336 - Apache HTTP Server Cross-Domain Header Exposure

2 days ago 3
ARTICLE AD BOX
CVE ID : CVE-2024-45336
Published : Jan. 28, 2025, 2:15 a.m. | 16 minutes ago
Description : The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article