Описание
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
A vulnerability was found in curl. This security flaw allows leak authentication or cookie header data on HTTP redirects to the same host but another port number. Sending the same set of headers to a server on a different port number is a problem for applications that pass on custom Authorization:
or Cookie:
headers. Those headers often contain privacy-sensitive information or data.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
.NET Core 3.1 on Red Hat Enterprise Linux | rh-dotnet31-curl | Out of support scope | ||
Red Hat Enterprise Linux 6 | curl | Out of support scope | ||
Red Hat Enterprise Linux 7 | curl | Out of support scope | ||
Red Hat JBoss Core Services | curl | Not affected | ||
Red Hat Software Collections | httpd24-curl | Will not fix | ||
Red Hat Enterprise Linux 8 | curl | Fixed | RHSA-2022:5313 | 30.06.2022 |
Red Hat Enterprise Linux 9 | curl | Fixed | RHSA-2022:5245 | 01.07.2022 |
Red Hat Enterprise Linux 9 | curl | Fixed | RHSA-2022:5245 | 01.07.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
HackerOne: CVE-2022-27776 Insufficiently protected credentials vulnerability might leak authentication or cookie header data
A insufficiently protected credentials vulnerability in fixed in curl ...
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
EPSS
4.3 Medium
CVSS3