logo

Database

Sensitive information sent insecurely In org.apache.httpcomponents:httpclient

Description

Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClient Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions