Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
Vulnerability Description
The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authorization, and all custom headers are forwarded to the redirect target.
CVSS Information
N/A
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Vulnerability Title
Kiota Java Libraries 输入验证错误漏洞
Vulnerability Description
Kiota Java Libraries是Microsoft开源的一个用于生成OpenAPI SDK的Java基础库集合。 Kiota Java Libraries 1.9.0版本存在输入验证错误漏洞,该漏洞源于RedirectHandler中间件在遵循3xx重定向到不同主机或方案时未能剥离敏感HTTP头,仅移除Authorization头,Cookie、Proxy-Authorization和所有自定义头被转发到重定向目标。
CVSS Information
N/A
Vulnerability Type
N/A