CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

  • Published Jan 28, 2025
  • CVSS 6.1 medium
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2024-45336 at the National Vulnerability Database