CVE Vulnerabilities

CVE-2025-4673

Published: Jun 11, 2025 | Modified: Jun 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.8 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Ubuntu
MEDIUM

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 10 RedHat golang-0:1.24.4-1.el10_0 *
Red Hat Enterprise Linux 10 RedHat opentelemetry-collector-0:0.127.0-3.el10_0 *
Red Hat Enterprise Linux 8 RedHat go-toolset:rhel8-8100020250705224704.a3795dee *
Red Hat Enterprise Linux 9 RedHat golang-0:1.24.4-1.el9_6 *
Red Hat Enterprise Linux 9 RedHat opentelemetry-collector-0:0.127.0-2.el9_6 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat opentelemetry-collector-0:0.127.0-2.el9_4 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/opentelemetry-collector-rhel8:sha256:93a3f6c10968431079bf0b637b029406d6a0bdc9521f3a02b062af7a3539995e *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/opentelemetry-rhel8-operator:sha256:5bb83d0b9387f51291c3977d37aab8a19e978a7dccf3d72cae0dabb66bd26df4 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/opentelemetry-target-allocator-rhel8:sha256:281913677308b5a7f0f834161ca1c1cf22e2686616f60057ac8ae61627f66861 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/tempo-gateway-opa-rhel8:sha256:34851d4dd94a887b27d0937a1238d09ac370b4ec06382fe880796dac86c4aa3e *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/tempo-gateway-rhel8:sha256:b1995ead9af6e923bd55ebdbed4c371b7f8bb58c46d6a36e9a25f9296f09a3f4 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/tempo-jaeger-query-rhel8:sha256:d1425fca630adab3f66b30eaf47010c2da892e2d635a721c493c1751f98f69b3 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/tempo-query-rhel8:sha256:e5302b8da7585229e8c123fa3a84720e46bca9abd76acfc31ae0273f3fd4f800 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/tempo-rhel8:sha256:1feaee0df48953c919df3ceb2dde3aa10345e69c0b1a7186a8a0fd6ab9b300f6 *
Red Hat OpenShift distributed tracing 3.6.1 RedHat rhosdt/tempo-rhel8-operator:sha256:d0783f1725e2452c74dd687ac3238634851b9e587cd5c1134e790a43cdd7cad5 *
Golang-1.22 Ubuntu esm-apps/jammy *
Golang-1.22 Ubuntu jammy *
Golang-1.22 Ubuntu noble *
Golang-1.22 Ubuntu oracular *
Golang-1.23 Ubuntu oracular *

References