/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-24xq-4h7w-5qjg

Published

Last updated

https://images.chainguard.dev/security/CGA-24xq-4h7w-5qjg
Package

hadoop-fips-3.3.6

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2011-1498
  • GHSA-gw85-4gmf-m7rh

Severity

Unknown

Summary

Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClient

Description

Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs