[BLFS Trac] #23287: libwww-perl-6.83 (Perl Module)

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23287: libwww-perl-6.83 (Perl Module)
-----------------------------+-----------------------
 Reporter:  Douglas R. Reno  |      Owner:  blfs-book
     Type:  enhancement      |     Status:  new
 Priority:  elevated         |  Milestone:  13.1
Component:  BOOK             |    Version:  git
 Severity:  normal           |   Keywords:
-----------------------------+-----------------------
 New point version

 I got an email at 9:07AM from CPAN Security:

 {{{
 ========================================================================
 CVE-2026-8368                                        CPAN Security Group
 ========================================================================

         CVE ID:  CVE-2026-8368
   Distribution:  libwww-perl
       Versions:  before 6.83

       MetaCPAN:  https://metacpan.org/dist/libwww-perl
       VCS Repo:  https://github.com/libwww-perl/libwww-perl


 LWP::UserAgent versions before 6.83 for Perl leak Authorization and
 Proxy-Authorization headers on cross-origin redirects

 Description
 -----------
 LWP::UserAgent versions before 6.83 for Perl leak Authorization and
 Proxy-Authorization headers on cross-origin redirects.

 On a 3xx response, the redirect handler strips only Host and Cookie
 before issuing the follow-up request. Caller-supplied Authorization and
 Proxy-Authorization headers are sent unchanged to the redirect target,
 including across scheme, host, or port changes.

 A redirect to an attacker controlled host therefore discloses the
 caller's credentials to that host.

 Problem types
 -------------
 - CWE-522 Insufficiently Protected Credentials

 Solutions
 ---------
 Upgrade to libwww-perl 6.83 or later.


 References
 ----------
 https://github.com/libwww-perl/libwww-
 perl/commit/9c4aeb6f2dd32f2b7eaf2d7827cade31ea6cb2c6.patch
 https://metacpan.org/release/OALDERS/libwww-perl-6.83/changes
 https://github.com/libwww-perl/libwww-perl/pull/512
 https://github.com/libwww-perl/libwww-perl/pull/284

 Timeline
 --------
 - 2026-05-11: Issue reported.
 - 2026-05-12: libwww-perl 6.83 released with fix.
 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23287>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.