Описание
When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.
Ссылки
- PatchVendor Advisory
- Vendor Advisory
- ExploitIssue TrackingThird Party Advisory
- Mailing ListPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.58.0 (включая) до 8.18.0 (исключая)
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
EPSS
Процентиль: 41%
0.00486
Низкий
3.1 Low
CVSS3
Дефекты
CWE-287
CWE-287
Связанные уязвимости
CVSS3: 3.1
ubuntu
9 месяцев назад
When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.
CVSS3: 4.7
redhat
9 месяцев назад
When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.
CVSS3: 3.1
debian
9 месяцев назад
When doing SSH-based transfers using either SCP or SFTP, and asked to ...
EPSS
Процентиль: 41%
0.00486
Низкий
3.1 Low
CVSS3
Дефекты
CWE-287
CWE-287