Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-31043
HistoryJun 10, 2022 - 12:00 a.m.

CVE-2022-31043

2022-06-1000:00:00
ubuntu.com
ubuntu.com
26

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

60.9%

Guzzle is an open source PHP HTTP client. In affected versions
Authorization headers on requests are sensitive information. On making a
request using the https scheme to a server which responds with a redirect
to a URI with the http scheme, we should not forward the Authorization
header on. This is much the same as to how we don’t forward on the header
if the host changes. Prior to this fix, https to http downgrades did
not result in the Authorization header being removed, only changes to the
host. Affected Guzzle 7 users should upgrade to Guzzle 7.4.4 as soon as
possible. Affected users using any earlier series of Guzzle should upgrade
to Guzzle 6.5.7 or 7.4.4. Users unable to upgrade may consider an
alternative approach which would be to use their own redirect middleware.
Alternately users may simply disable redirects all together if redirects
are not expected or required.

OSVersionArchitecturePackageVersionFilename
ubuntu23.10noarchguzzle< anyUNKNOWN
ubuntu24.04noarchguzzle< anyUNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

60.9%