CVE-2025-46421 Information
Apr 25, 2025
cve
Description
A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Reference
https://access.redhat.com/security/cve/CVE-2025-46421 https://bugzilla.redhat.com/show_bug.cgi?id=2361962
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
6.8
Share on: