The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

Project Subscriptions

Vendors Products
Ceph Storage Subscribe
Enterprise Linux Subscribe
Logging Subscribe
Openshift Distributed Tracing Subscribe
Rhel Eus Subscribe
Rhel Satellite Client Subscribe
Service Mesh Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-41740 The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
Ubuntu USN Ubuntu USN USN-7574-1 Go vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00032}

epss

{'score': 0.00035}


Thu, 15 May 2025 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Satellite Client
CPEs cpe:/a:redhat:rhel_satellite_client:6::el8
cpe:/a:redhat:rhel_satellite_client:6::el9
Vendors & Products Redhat rhel Satellite Client

Wed, 14 May 2025 03:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10.0

Thu, 08 May 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ceph Storage
CPEs cpe:/a:redhat:acm:2.11::el9
cpe:/a:redhat:ceph_storage:7.1::el9
Vendors & Products Redhat ceph Storage

Wed, 30 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat acm
CPEs cpe:/a:redhat:acm:2.12::el9
Vendors & Products Redhat acm

Wed, 16 Apr 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat service Mesh
CPEs cpe:/a:redhat:service_mesh:2.5::el8
Vendors & Products Redhat service Mesh

Thu, 10 Apr 2025 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8

Fri, 04 Apr 2025 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Eus
CPEs cpe:/a:redhat:rhel_eus:9.4
Vendors & Products Redhat rhel Eus

Fri, 28 Mar 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:9
Vendors & Products Redhat enterprise Linux

Thu, 27 Mar 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat logging
CPEs cpe:/a:redhat:logging:6.1::el9
Vendors & Products Redhat logging

Fri, 14 Mar 2025 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat openshift Distributed Tracing
CPEs cpe:/a:redhat:openshift_distributed_tracing:3.5::el8
Vendors & Products Redhat
Redhat openshift Distributed Tracing

Fri, 21 Feb 2025 18:45:00 +0000

Type Values Removed Values Added
References

Tue, 28 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 28 Jan 2025 01:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
Title golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect Sensitive headers incorrectly sent after cross-domain redirect in net/http
References

Fri, 24 Jan 2025 01:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect
Weaknesses CWE-200
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2025-09-18T18:41:11.116Z

Reserved: 2024-08-27T19:41:58.555Z

Link: CVE-2024-45336

cve-icon Vulnrichment

Updated: 2025-02-21T18:03:31.299Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-28T02:15:28.807

Modified: 2025-02-21T18:15:17.400

Link: CVE-2024-45336

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-01-17T00:00:00Z

Links: CVE-2024-45336 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses