{"id":"DEBIAN-CVE-2011-1498","details":"Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.","modified":"2026-09-14T06:47:29.381628615Z","published":"2011-07-07T21:55:01.663Z","upstream":["CVE-2011-1498"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2011-1498"}],"affected":[{"package":{"name":"httpcomponents-client","ecosystem":"Debian:12","purl":"pkg:deb/debian/httpcomponents-client?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-1498.json"}},{"package":{"name":"httpcomponents-client","ecosystem":"Debian:13","purl":"pkg:deb/debian/httpcomponents-client?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-1498.json"}},{"package":{"name":"httpcomponents-client","ecosystem":"Debian:14","purl":"pkg:deb/debian/httpcomponents-client?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-1498.json"}}],"schema_version":"1.9.0"}