CVE-2024-45336
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Jan 28, 2025
Summary
CVE-2024-45336 is a vulnerability affecting HTTP clients that drop sensitive headers after following a cross-domain redirect. For instance, if a request to a.com with an Authorization header is redirected to b.com, the Authorization header will not be sent to b.com. However, if the client receives a subsequent same-domain redirect (such as from b.com to b.com/1 and then to b.com/2), the sensitive headers will be incorrectly restored and sent. This issue poses a risk for unauthorized access to protected resources through manipulation of redirect chains.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Google Go