CVE-2025-46421

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.
Configurations

No configuration.

History

24 Apr 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-24 13:15

Updated : 2025-04-24 13:15


NVD link : CVE-2025-46421

Mitre link : CVE-2025-46421

CVE.ORG link : CVE-2025-46421


JSON object : View

Products Affected

No product.

CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere