Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets
Vulnerability Description
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire. The HTTP::Tiny POD note that "Authorization headers will not be included in a redirected request" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.
CVSS Information
N/A
Vulnerability Type
不充分的凭证保护机制
Vulnerability Title
HAARG HTTP-Tiny 信任管理问题漏洞
Vulnerability Description
HAARG HTTP::Tiny是HAARG的Perl HTTP客户端库。 HAARG HTTP-Tiny 0.095之前版本存在信任管理问题漏洞,该漏洞源于未检查重定向目标是否与原始URL同源,导致调用者提供的Authorization、Cookie和Proxy-Authorization标头被转发到跨域重定向目标。
CVSS Information
N/A
Vulnerability Type
N/A