漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch
Vulnerability Description
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N
Vulnerability Type
通过发送数据的信息暴露
Vulnerability Title
libsoup 信息泄露漏洞
Vulnerability Description
libsoup是libsoup团队开源的一个HTTP库。 libsoup存在信息泄露漏洞,该漏洞源于SoupAuthManager在缓存代理身份验证凭据时未限定作用域至代理主机和端口,导致代理配置更改后缓存的Proxy-Authorization标头发送至新代理,可能泄露凭据。
CVSS Information
N/A
Vulnerability Type
N/A