« Volver al listado

CVE-2011-1498

Estado: ModificadaMedia (4.3)—

Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-1498",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-07-07T21:55:01.663",
  "references": [
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061440.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://marc.info/?l=httpclient-users&m=129853896315461&w=2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://marc.info/?l=httpclient-users&m=129856318011586&w=2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://marc.info/?l=httpclient-users&m=129857589129183&w=2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://marc.info/?l=httpclient-users&m=129858274406594&w=2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://marc.info/?l=httpclient-users&m=129858299106950&w=2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2011/04/07/7",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2011/04/08/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://securityreason.com/securityalert/8298",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.1.x.txt",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/153049",
      "tags": [
        "US Government Resource"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/46974",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=709531",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://issues.apache.org/jira/browse/HTTPCLIENT-1061",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061440.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=httpclient-users&m=129853896315461&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=httpclient-users&m=129856318011586&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=httpclient-users&m=129857589129183&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=httpclient-users&m=129858274406594&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=httpclient-users&m=129858299106950&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2011/04/07/7",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2011/04/08/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/8298",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.1.x.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/153049",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/46974",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=709531",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://issues.apache.org/jira/browse/HTTPCLIENT-1061",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header."
    },
    {
      "lang": "es",
      "value": "Apache HttpClient v4.x antes de v4.1.1 en Apache HttpComponents, cuando se utiliza con un servidor proxy de autenticación, envía el encabezado Proxy-Authorization al servidor de origen, lo que permite obtener información sensible a los servidores Web remotos mediante la comprobación de esta cabecera."
    }
  ],
  "lastModified": "2026-06-16T23:29:30.027",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:httpclient:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4C91BDB-E3D5-4891-9F29-6B8B5D32A54D"
            },
            {
              "criteria": "cpe:2.3:a:apache:httpclient:4.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA42463A-DFD4-4609-9871-98348B3E98B8"
            },
            {
              "criteria": "cpe:2.3:a:apache:httpclient:4.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D07113CF-6A5D-4619-B7C8-20FFC3D9D1E7"
            },
            {
              "criteria": "cpe:2.3:a:apache:httpclient:4.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AE2C617-BF81-437B-BC04-7620EE6FA6AE"
            },
            {
              "criteria": "cpe:2.3:a:apache:httpclient:4.0:alpha4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE97A012-0D85-4EF1-ABFB-BE619F3289E1"
            },
            {
              "criteria": "cpe:2.3:a:apache:httpclient:4.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82584BFB-BC70-4B3F-BC90-A9416E62EF35"
            },
            {
              "criteria": "cpe:2.3:a:apache:httpclient:4.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C83F8D40-F7C5-4543-81E1-40085A2E7341"
            },
            {
              "criteria": "cpe:2.3:a:apache:httpclient:4.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4922F122-1D31-4D76-9D43-F4F95720939B"
            },
            {
              "criteria": "cpe:2.3:a:apache:httpclient:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D95BD2A2-0765-42F4-A3CA-22DB96E195B0"
            },
            {
              "criteria": "cpe:2.3:a:apache:httpclient:4.1:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "246968EA-BEEF-4046-B535-629C03643852"
            },
            {
              "criteria": "cpe:2.3:a:apache:httpclient:4.1:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5FE210D-BB5E-4305-A846-4A18BCEC7807"
            },
            {
              "criteria": "cpe:2.3:a:apache:httpclient:4.1:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "956E366E-8E89-43B7-82EB-1757F4F519C5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}