Re: [BLFS Trac] #23287: libwww-perl-6.83 (Perl Module)

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23287: libwww-perl-6.83 (Perl Module)
-----------------------------+-------------------------------
 Reporter:  Douglas R. Reno  |       Owner:  SecurityAdvisory
     Type:  enhancement      |      Status:  new
 Priority:  elevated         |   Milestone:  13.1
Component:  BOOK             |     Version:  git
 Severity:  normal           |  Resolution:
 Keywords:                   |
-----------------------------+-------------------------------
Changes (by Joe Locash):

 * owner:  Joe Locash => SecurityAdvisory
 * status:  assigned => new

Comment:

 {{{
 6.83      2026-05-12 11:41:48Z
     - LWP::UserAgent now strips Authorization and Proxy-Authorization
 headers
       on cross-origin redirects (a different scheme, host, or port) to
 prevent
       credential leakage to the redirect target. Same-origin redirects
 retain
       credentials. Opt out with allow_credentialed_redirects => 1.
       CVE-2026-8368 reported by Kai Zen; PoC and initial patch by Stig
       Palmquist.
     - LWP::UserAgent now refuses https to http redirects by default to
 prevent
       leaking remaining request headers and bodies over plaintext. Opt in
 with
       allow_downgrade => 1. Related hardening alongside CVE-2026-8368; PoC
 by
       Stig Palmquist.
 }}}
 Fixed at b281d8bd70. Leaving open for SA.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23287#comment:2>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.