← Back to CVE List

CVE-2023-45289

Published: 2024-03-05T23:15Z
Last Modified: 2024-11-21T08:26Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt