Show plain JSON{"cve": {"data_type": "CVE", "references": {"reference_data": [{"url": "http://marc.info/?l=httpclient-users&m=129857589129183&w=2", "name": "[httpclient-users] 20110224 RE: Proxy-Authorization header received on server side", "tags": [], "refsource": "MLIST"}, {"url": "http://marc.info/?l=httpclient-users&m=129856318011586&w=2", "name": "[httpclient-users] 20110224 Re: Proxy-Authorization header received on server side", "tags": [], "refsource": "MLIST"}, {"url": "https://issues.apache.org/jira/browse/HTTPCLIENT-1061", "name": "https://issues.apache.org/jira/browse/HTTPCLIENT-1061", "tags": [], "refsource": "CONFIRM"}, {"url": "http://openwall.com/lists/oss-security/2011/04/07/7", "name": "[oss-security] 20110407 Apache HttpClient CVE request [VU#153049]", "tags": [], "refsource": "MLIST"}, {"url": "https://bugzilla.redhat.com/show_bug.cgi?id=709531", "name": "https://bugzilla.redhat.com/show_bug.cgi?id=709531", "tags": [], "refsource": "CONFIRM"}, {"url": "http://marc.info/?l=httpclient-users&m=129858274406594&w=2", "name": "[httpclient-users] 20110224 Re: Proxy-Authorization header received on server side", "tags": [], "refsource": "MLIST"}, {"url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061440.html", "name": "FEDORA-2011-7747", "tags": [], "refsource": "FEDORA"}, {"url": "http://www.securityfocus.com/bid/46974", "name": "46974", "tags": [], "refsource": "BID"}, {"url": "http://marc.info/?l=httpclient-users&m=129858299106950&w=2", "name": "[httpclient-users] 20110224 RE: Proxy-Authorization header received on server side", "tags": [], "refsource": "MLIST"}, {"url": "http://marc.info/?l=httpclient-users&m=129853896315461&w=2", "name": "[httpclient-users] 20110224 Proxy-Authorization header received on server side", "tags": [], "refsource": "MLIST"}, {"url": "http://openwall.com/lists/oss-security/2011/04/08/1", "name": "[oss-security] 20110408 Re: Apache HttpClient CVE request [VU#153049]", "tags": [], "refsource": "MLIST"}, {"url": "http://www.kb.cert.org/vuls/id/153049", "name": "VU#153049", "tags": ["US Government Resource"], "refsource": "CERT-VN"}, {"url": "http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.1.x.txt", "name": "http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.1.x.txt", "tags": [], "refsource": "CONFIRM"}, {"url": "http://securityreason.com/securityalert/8298", "name": "8298", "tags": [], "refsource": "SREASON"}]}, "data_format": "MITRE", "description": {"description_data": [{"lang": "en", "value": "Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "en", "value": "CWE-200"}]}]}, "data_version": "4.0", "CVE_data_meta": {"ID": "CVE-2011-1498", "ASSIGNER": "secalert@redhat.com"}}, "impact": {"baseMetricV2": {"cvssV2": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "severity": "MEDIUM", "impactScore": 2.9, "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}}, "publishedDate": "2011-07-07T21:55Z", "configurations": {"nodes": [{"children": [], "operator": "OR", "cpe_match": [{"cpe23Uri": "cpe:2.3:a:apache:httpclient:4.0:alpha3:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:apache:httpclient:4.0:alpha4:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:apache:httpclient:4.0:beta1:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:apache:httpclient:4.1:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:apache:httpclient:4.0:alpha1:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:apache:httpclient:4.0:alpha2:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:apache:httpclient:4.1:alpha2:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:apache:httpclient:4.1:beta1:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:apache:httpclient:4.0.1:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:apache:httpclient:4.1:alpha1:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:apache:httpclient:4.0:beta2:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:apache:httpclient:4.0:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}]}], "CVE_data_version": "4.0"}, "lastModifiedDate": "2011-09-22T03:30Z"}