CVE Vulnerabilities

CVE-2025-4673

Published: Jun 11, 2025 | Modified: Jun 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.8 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Ubuntu
MEDIUM

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 10 RedHat golang-0:1.24.4-1.el10_0 *
Red Hat Enterprise Linux 8 RedHat go-toolset:rhel8-8100020250705224704.a3795dee *
Red Hat Enterprise Linux 9 RedHat golang-0:1.24.4-1.el9_6 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat registry.redhat.io/rhosdt/opentelemetry-collector-rhel8:sha256:40535c017d2730645c57c44b32b4df1613585cc19c052fe472ccbf543a659c42 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat registry.redhat.io/rhosdt/opentelemetry-rhel8-operator:sha256:39378c1e705973edca5f52f422b5c3693aaf5d2f22fb320d7676086b2cf846ba *
Red Hat OpenShift distributed tracing 3.6.1 RedHat registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel8:sha256:18ca3c44f6f25cbfe67842a0b2c9491a8247a64dbd166f188dccf0a84cfd3e67 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8:sha256:34851d4dd94a887b27d0937a1238d09ac370b4ec06382fe880796dac86c4aa3e *
Red Hat OpenShift distributed tracing 3.6.1 RedHat registry.redhat.io/rhosdt/tempo-gateway-rhel8:sha256:cd011375e307f5cef74d4819f37567f6291259eb1d2795f0cf4b8cb8a90004e0 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8:sha256:2a37885dbd9735167854119a546f9ce1b37454a2b57d283fbd8da890c01db767 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat registry.redhat.io/rhosdt/tempo-query-rhel8:sha256:8f2da1e0fc45a36cffbe91f9a1c4449eb0c71671865b7194951ad727c9f7b064 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat registry.redhat.io/rhosdt/tempo-rhel8:sha256:3a3719e3683051967d548de708e178640f848933c99efc3955ca915a46bcb675 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat registry.redhat.io/rhosdt/tempo-rhel8-operator:sha256:54c5403a8a9e0300233e75a04318013e9dbe3d894be691927d27dc2fe53fddc0 *
Golang-1.22 Ubuntu esm-apps/jammy *
Golang-1.22 Ubuntu jammy *
Golang-1.22 Ubuntu noble *
Golang-1.22 Ubuntu oracular *
Golang-1.23 Ubuntu oracular *

References