Уязвимость утечки данных аутентификации или заголовков с cookie на HTTP-перенаправлениях в curl
Описание
Уязвимость недостаточно защищённых учетных данных в curl позволяет утечку данных аутентификации или заголовков cookie при HTTP-перенаправлениях на тот же хост, но с другим номером порта.
Затронутые версии ПО
- curl до версии 7.83.0
Тип уязвимости
Утечка информации
Ссылки
- ExploitThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одновременно
Одно из
Одновременно
Одновременно
Одновременно
Одновременно
Одно из
EPSS
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
HackerOne: CVE-2022-27776 Insufficiently protected credentials vulnerability might leak authentication or cookie header data
A insufficiently protected credentials vulnerability in fixed in curl ...
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
EPSS
6.5 Medium
CVSS3
4.3 Medium
CVSS2