Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3153

Опубликовано: 29 апр. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.2curlWill not fix
Red Hat Enterprise Linux 5curlWill not fix
Red Hat Enterprise Linux 6curlWill not fix
Red Hat Enterprise Linux 7curlWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=1217341curl: sensitive HTTP server headers also sent to proxies

EPSS

Процентиль: 93%
0.0976
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.

nvd
почти 11 лет назад

The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.

debian
почти 11 лет назад

The default configuration for cURL and libcurl before 7.42.1 sends cus ...

github
больше 3 лет назад

The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.

suse-cvrf
почти 11 лет назад

Security update for curl

EPSS

Процентиль: 93%
0.0976
Низкий

4.3 Medium

CVSS2