CVE-2025-22870 - CERT CVE
ID CVE-2025-22870
Sažetak Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.
Reference
CVSS
Base: 4.4
Impact: 2.5
Exploitability:1.8
Pristup
VektorSloženostAutentikacija
LOCAL LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
LOW NONE LOW
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Zadnje važnije ažuriranje 09-05-2025 - 20:15
Objavljeno 12-03-2025 - 19:15