A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libsoup | Gnome | - (including) | - (including) |
| Enterprise_linux | Redhat | 7.0 (including) | 7.0 (including) |
| Enterprise_linux | Redhat | 8.0 (including) | 8.0 (including) |
| Enterprise_linux | Redhat | 9.0 (including) | 9.0 (including) |
| Enterprise_linux | Redhat | 10.0 (including) | 10.0 (including) |
| Red Hat Enterprise Linux 10 | RedHat | libsoup3-0:3.6.5-3.el10_1.11 | * |
| Red Hat Enterprise Linux 10 | RedHat | libsoup3-0:3.6.5-3.el10_2.11 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | libsoup3-0:3.6.5-3.el10_0.15 | * |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | RedHat | libsoup-0:2.62.2-12.el7_9 | * |
| Red Hat Enterprise Linux 8 | RedHat | libsoup-0:2.62.3-14.el8_10 | * |
| Red Hat Enterprise Linux 8 | RedHat | libsoup-0:2.62.3-14.el8_10 | * |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | libsoup-0:2.62.3-2.el8_4.9 | * |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | libsoup-0:2.62.3-2.el8_4.9 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | libsoup-0:2.62.3-2.el8_6.9 | * |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | RedHat | libsoup-0:2.62.3-2.el8_6.9 | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | libsoup-0:2.62.3-3.el8_8.9 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | libsoup-0:2.62.3-3.el8_8.9 | * |
| Red Hat Enterprise Linux 9 | RedHat | libsoup-0:2.72.0-12.el9_7.6 | * |
| Red Hat Enterprise Linux 9 | RedHat | libsoup-0:2.72.0-16.el9_8.1 | * |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | libsoup-0:2.72.0-8.el9_0.10 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | libsoup-0:2.72.0-8.el9_2.11 | * |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | RedHat | libsoup-0:2.72.0-8.el9_4.10 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | libsoup-0:2.72.0-10.el9_6.7 | * |
| Libsoup2.4 | Ubuntu | esm-infra/xenial | * |