CVE-2011-1498

Publication date 7 July 2011

Last updated 24 July 2024


Ubuntu priority

Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.

Status

Package Ubuntu Release Status
httpcomponents-client 12.10 quantal
Not affected
12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty Ignored end of life
10.10 maverick Ignored end of life
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release