Re: [BLFS Trac] #23287: libwww-perl-6.83 (Perl Module)
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23287: libwww-perl-6.83 (Perl Module)
-----------------------------+-------------------------------
Reporter: Douglas R. Reno | Owner: SecurityAdvisory
Type: enhancement | Status: new
Priority: elevated | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-----------------------------+-------------------------------
Changes (by Joe Locash):
* owner: Joe Locash => SecurityAdvisory
* status: assigned => new
Comment:
{{{
6.83 2026-05-12 11:41:48Z
- LWP::UserAgent now strips Authorization and Proxy-Authorization
headers
on cross-origin redirects (a different scheme, host, or port) to
prevent
credential leakage to the redirect target. Same-origin redirects
retain
credentials. Opt out with allow_credentialed_redirects => 1.
CVE-2026-8368 reported by Kai Zen; PoC and initial patch by Stig
Palmquist.
- LWP::UserAgent now refuses https to http redirects by default to
prevent
leaking remaining request headers and bodies over plaintext. Opt in
with
allow_downgrade => 1. Related hardening alongside CVE-2026-8368; PoC
by
Stig Palmquist.
}}}
Fixed at b281d8bd70. Leaving open for SA.
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23287#comment:2>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page