Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-22923

Опубликовано: 05 авг. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.6
CVSS3: 5.3

Описание

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

РелизСтатусПримечание
bionic

not-affected

code not compiled
devel

not-affected

code not compiled
esm-infra-legacy/trusty

not-affected

code not compiled
esm-infra/bionic

not-affected

code not compiled
esm-infra/focal

not-affected

code not compiled
esm-infra/xenial

not-affected

code not compiled
focal

not-affected

code not compiled
groovy

not-affected

code not compiled
hirsute

not-affected

code not compiled
impish

not-affected

code not compiled

Показывать по

Ссылки на источники

EPSS

Процентиль: 20%
0.00064
Низкий

2.6 Low

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
redhat
почти 4 года назад

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

CVSS3: 5.3
nvd
почти 4 года назад

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

CVSS3: 5.3
debian
почти 4 года назад

When curl is instructed to get content using the metalink feature, and ...

CVSS3: 5.3
github
около 3 лет назад

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

CVSS3: 5.3
fstec
почти 4 года назад

Уязвимость программного средства для взаимодействия с серверами CURL, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 20%
0.00064
Низкий

2.6 Low

CVSS2

5.3 Medium

CVSS3

Уязвимость CVE-2021-22923