Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-27774

Опубликовано: 27 апр. 2022
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.

A vulnerability was found in curl. This security flaw allows leaking credentials to other servers when it follows redirects from auth-protected HTTP(S) URLs to other protocols and port numbers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 3.1 on Red Hat Enterprise Linuxrh-dotnet31-curlOut of support scope
Red Hat Enterprise Linux 6curlOut of support scope
Red Hat Enterprise Linux 7curlOut of support scope
Red Hat JBoss Core ServicescurlNot affected
Red Hat Software Collectionshttpd24-curlWill not fix
Red Hat Enterprise Linux 8curlFixedRHSA-2022:531330.06.2022
Red Hat Enterprise Linux 9curlFixedRHSA-2022:524501.07.2022
Red Hat Enterprise Linux 9curlFixedRHSA-2022:524501.07.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-522

EPSS

Процентиль: 44%
0.00215
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
ubuntu
около 3 лет назад

An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.

CVSS3: 5.7
nvd
около 3 лет назад

An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.

CVSS3: 5.7
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 5.7
debian
около 3 лет назад

An insufficiently protected credentials vulnerability exists in curl 4 ...

CVSS3: 5.7
github
около 3 лет назад

An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.

EPSS

Процентиль: 44%
0.00215
Низкий

5 Medium

CVSS3