4.3

CVE-2011-1498

Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.

Data is provided by the National Vulnerability Database (NVD)
ApacheHttpclient Version4.0
ApacheHttpclient Version4.0 Updatealpha1
ApacheHttpclient Version4.0 Updatealpha2
ApacheHttpclient Version4.0 Updatealpha3
ApacheHttpclient Version4.0 Updatealpha4
ApacheHttpclient Version4.0 Updatebeta1
ApacheHttpclient Version4.0 Updatebeta2
ApacheHttpclient Version4.0.1
ApacheHttpclient Version4.1
ApacheHttpclient Version4.1 Updatealpha1
ApacheHttpclient Version4.1 Updatealpha2
ApacheHttpclient Version4.1 Updatebeta1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.21% 0.895
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.