CVE Vulnerabilities

CVE-2025-4673

Published: Jun 11, 2025 | Modified: Jun 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.8 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatgolang-0:1.24.4-1.el10_0*
Red Hat Enterprise Linux 10RedHatopentelemetry-collector-0:0.127.0-3.el10_0*
Red Hat Enterprise Linux 8RedHatgo-toolset:rhel8-8100020250705224704.a3795dee*
Red Hat Enterprise Linux 9RedHatgolang-0:1.24.4-1.el9_6*
Red Hat Enterprise Linux 9RedHatopentelemetry-collector-0:0.127.0-2.el9_6*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatopentelemetry-collector-0:0.127.0-2.el9_4*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/opentelemetry-collector-rhel8:sha256:1faa5daf085b0844740653d96711b3fcfa766a77224fb523335d877b8e314b57*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/opentelemetry-rhel8-operator:sha256:39378c1e705973edca5f52f422b5c3693aaf5d2f22fb320d7676086b2cf846ba*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/opentelemetry-target-allocator-rhel8:sha256:18ca3c44f6f25cbfe67842a0b2c9491a8247a64dbd166f188dccf0a84cfd3e67*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/tempo-gateway-opa-rhel8:sha256:34851d4dd94a887b27d0937a1238d09ac370b4ec06382fe880796dac86c4aa3e*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/tempo-gateway-rhel8:sha256:e8f3e4113f56564a287bad34721440b00ef600fb99f0dc454dd9c9581e57e696*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/tempo-jaeger-query-rhel8:sha256:faad36621dda484f7883da35873b9f288f6c7a1332815bc857531de032c38068*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/tempo-query-rhel8:sha256:c34a7574e3c6af4c82bee38e581d047613f8931c12d89924764f46b565bf3117*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/tempo-rhel8:sha256:3a3719e3683051967d548de708e178640f848933c99efc3955ca915a46bcb675*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/tempo-rhel8-operator:sha256:d0783f1725e2452c74dd687ac3238634851b9e587cd5c1134e790a43cdd7cad5*
Golang-1.22Ubuntuesm-apps/jammy*
Golang-1.22Ubuntujammy*
Golang-1.22Ubuntunoble*
Golang-1.22Ubuntuoracular*
Golang-1.23Ubuntuoracular*
Golang-1.23Ubuntuplucky*
Golang-1.24Ubuntuplucky*

References