HomeDefault status
unaffected
Any version before 1.23.10
affected
1.24.0-0 (semver) before 1.24.4
affected
Description
Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.
Problem types
CWE-201: Insertion of Sensitive Information Into Sent Data
Product status
Any version before 1.23.10
1.24.0-0 (semver) before 1.24.4
Credits
Takeshi Kaneko (GMO Cybersecurity by Ierae, Inc.)
References
groups.google.com/g/golang-announce/c/ufZ8WpEsA3A