Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13041
HistoryJan 15, 2019 - 9:25 a.m.

Information Disclosure

2019-01-1509:25:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.036 Low

EPSS

Percentile

91.7%

System.Net.Http in rh-dotnetcore10 and rh-dotnetcore11 is vulnerable to an information disclosure. The library does not clear it’s authentication headers during redirection, allowing a malicious user to use a redirect to gain access to information in the authentication header.