CVE Vulnerabilities

CVE-2025-4673

Published: Jun 11, 2025 | Modified: Apr 15, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.8 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatgolang-0:1.24.4-1.el10_0*
Red Hat Enterprise Linux 10RedHatopentelemetry-collector-0:0.127.0-3.el10_0*
Red Hat Enterprise Linux 8RedHatgo-toolset:rhel8-8100020250705224704.a3795dee*
Red Hat Enterprise Linux 9RedHatgolang-0:1.24.4-1.el9_6*
Red Hat Enterprise Linux 9RedHatopentelemetry-collector-0:0.127.0-2.el9_6*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatopentelemetry-collector-0:0.127.0-2.el9_4*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/opentelemetry-collector-rhel8:rhosdt-3.6-1752046452*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/opentelemetry-rhel8-operator:rhosdt-3.6-1752046437*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/opentelemetry-target-allocator-rhel8:rhosdt-3.6-1752046439*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/tempo-gateway-opa-rhel8:rhosdt-3.6-1752070865*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/tempo-gateway-rhel8:rhosdt-3.6-1752070873*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/tempo-jaeger-query-rhel8:rhosdt-3.6-1751993590*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/tempo-query-rhel8:rhosdt-3.6-1752070827*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/tempo-rhel8:rhosdt-3.6-1752070833*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/tempo-rhel8-operator:rhosdt-3.6-1752070866*
Golang-1.10Ubuntuesm-infra/xenial*
Golang-1.13Ubuntuesm-apps/xenial*
Golang-1.18Ubuntuesm-apps/xenial*
Golang-1.22Ubuntuesm-apps/jammy*
Golang-1.22Ubuntujammy*
Golang-1.22Ubuntunoble*
Golang-1.22Ubuntuoracular*
Golang-1.23Ubuntuoracular*
Golang-1.23Ubuntuplucky*
Golang-1.24Ubuntuplucky*
Golang-1.6Ubuntuesm-infra/xenial*

References