CVE Vulnerabilities

CVE-2025-4673

Published: Jun 11, 2025 | Modified: Jun 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.8 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Ubuntu
MEDIUM

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 10 RedHat golang-0:1.24.4-1.el10_0 *
Red Hat Enterprise Linux 10 RedHat opentelemetry-collector-0:0.127.0-3.el10_0 *
Red Hat Enterprise Linux 8 RedHat go-toolset:rhel8-8100020250705224704.a3795dee *
Red Hat Enterprise Linux 9 RedHat golang-0:1.24.4-1.el9_6 *
Red Hat Enterprise Linux 9 RedHat opentelemetry-collector-0:0.127.0-2.el9_6 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat opentelemetry-collector-0:0.127.0-2.el9_4 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/opentelemetry-collector-rhel8:sha256:40535c017d2730645c57c44b32b4df1613585cc19c052fe472ccbf543a659c42 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/opentelemetry-rhel8-operator:sha256:5bb83d0b9387f51291c3977d37aab8a19e978a7dccf3d72cae0dabb66bd26df4 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/opentelemetry-target-allocator-rhel8:sha256:46090c79b193de2028b4c994d3013fec7102f3b10673ecd09b017be4de7bf9f6 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/tempo-gateway-opa-rhel8:sha256:3e188c2073ae9099a3057c55d9366b6d1ec290b0016afa85f632c00cc4b778fa *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/tempo-gateway-rhel8:sha256:b1995ead9af6e923bd55ebdbed4c371b7f8bb58c46d6a36e9a25f9296f09a3f4 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/tempo-jaeger-query-rhel8:sha256:2a37885dbd9735167854119a546f9ce1b37454a2b57d283fbd8da890c01db767 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/tempo-query-rhel8:sha256:c34a7574e3c6af4c82bee38e581d047613f8931c12d89924764f46b565bf3117 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/tempo-rhel8:sha256:3a3719e3683051967d548de708e178640f848933c99efc3955ca915a46bcb675 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/tempo-rhel8-operator:sha256:e0319f6e008b9acca2b111406b25238d1e75ca95b18b09365886a617d2a38882 *
Golang-1.22 Ubuntu esm-apps/jammy *
Golang-1.22 Ubuntu jammy *
Golang-1.22 Ubuntu noble *
Golang-1.22 Ubuntu oracular *
Golang-1.23 Ubuntu oracular *

References