The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Enterprise Linux 8 | RedHat | go-toolset:rhel8-8100020250321121115.a3795dee | * |
Red Hat Enterprise Linux 9 | RedHat | opentelemetry-collector-0:0.107.0-8.el9_5 | * |
Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | opentelemetry-collector-0:0.107.0-7.el9_4 | * |
RHOL-6.1-RHEL-9 | RedHat | openshift-logging/cluster-logging-operator-bundle:v6.1.4-10 | * |
RHOL-6.1-RHEL-9 | RedHat | openshift-logging/cluster-logging-rhel9-operator:v6.1.4-5 | * |
RHOL-6.1-RHEL-9 | RedHat | openshift-logging/eventrouter-rhel9:v0.4.0-356 | * |
RHOL-6.1-RHEL-9 | RedHat | openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-337 | * |
RHOL-6.1-RHEL-9 | RedHat | openshift-logging/logging-loki-rhel9:v3.4.2-6 | * |
RHOL-6.1-RHEL-9 | RedHat | openshift-logging/loki-operator-bundle:v6.1.4-13 | * |
RHOL-6.1-RHEL-9 | RedHat | openshift-logging/loki-rhel9-operator:v6.1.4-7 | * |
RHOL-6.1-RHEL-9 | RedHat | openshift-logging/lokistack-gateway-rhel9:v0.1.0-752 | * |
RHOL-6.1-RHEL-9 | RedHat | openshift-logging/opa-openshift-rhel9:v0.1.0-369 | * |
RHOL-6.1-RHEL-9 | RedHat | openshift-logging/vector-rhel9:v0.37.1-34 | * |
Red Hat OpenShift distributed tracing 3.5.1 | RedHat | registry.redhat.io/rhosdt/opentelemetry-rhel8-operator:sha256:7e0320614f3be4e8bb1442d5890d2a6cebaf0a1038599d6afbf50daca91e1d65 | * |
Golang | Ubuntu | trusty | * |
Golang-1.10 | Ubuntu | bionic | * |
Golang-1.10 | Ubuntu | trusty | * |
Golang-1.10 | Ubuntu | trusty/esm | * |
Golang-1.10 | Ubuntu | xenial | * |
Golang-1.13 | Ubuntu | bionic | * |
Golang-1.13 | Ubuntu | xenial | * |
Golang-1.16 | Ubuntu | bionic | * |
Golang-1.18 | Ubuntu | bionic | * |
Golang-1.22 | Ubuntu | upstream | * |
Golang-1.23 | Ubuntu | upstream | * |
Golang-1.6 | Ubuntu | trusty | * |
Golang-1.6 | Ubuntu | xenial | * |
Golang-1.8 | Ubuntu | bionic | * |
Golang-1.9 | Ubuntu | bionic | * |