Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HttpClient 信息泄露漏洞
Vulnerability Description
HttpClient是美国阿帕奇(Apache)基金会的一个 Java 编写的访问HTTP资源的客户端程序。该程序用于使用HTTP协议访问网络资源。 Apache HttpClient 4.1.1之前的4.x版本存在信息泄露漏洞,该漏洞源于使用认证代理服务器时会向原始服务器发送Proxy-Authorization头。远程攻击者可通过记录此头获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A