Name
CVE-2025-46421
Description
A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.
CWEs
Published Date
Updated Date
Workaround
-
Advisories
Analysis#
Vulnerability Ratings#
6.8
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
libsoup (buildroot:2025.02.x)
#
Title
Author
Resolve
1
session: Strip authentication credentails on
Patrick Griffis <pgriffis@igalia.com>
CVE-2025-46421
libsoup (buildroot:master)
#
Title
Author
Resolve
1
session: Strip authentication credentails on
Patrick Griffis <pgriffis@igalia.com>
CVE-2025-46421
libsoup (yocto:kirkstone)
#
Title
Author
Resolve
1
session: Strip authentication credentails on cross-origin
Patrick Griffis <pgriffis@igalia.com>
CVE-2025-46421
libsoup-2.4 (yocto:kirkstone)
#
Title
Author
Resolve
1
session: Strip authentication credentails on
Patrick Griffis <pgriffis@igalia.com>
CVE-2025-46421
libsoup-2.4 (yocto:scarthgap)
#
Title
Author
Resolve
1
session: Strip authentication credentails on
Patrick Griffis <pgriffis@igalia.com>
CVE-2025-46421