Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-14524

Опубликовано: 08 янв. 2026
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 5.3

Описание

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

РелизСтатусПримечание
devel

not-affected

8.18.0
esm-infra-legacy/trusty

ignored

changes too intrusive
esm-infra/bionic

ignored

changes too intrusive
esm-infra/focal

ignored

changes too intrusive
esm-infra/xenial

ignored

changes too intrusive
jammy

released

7.81.0-1ubuntu1.22
noble

released

8.5.0-2ubuntu10.7
plucky

ignored

end of life, was needed
questing

released

8.14.1-2ubuntu1.1
upstream

pending

8.18.0-1

Показывать по

EPSS

Процентиль: 7%
0.00026
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

CVSS3: 5.3
msrc
3 месяца назад

bearer token leak on cross-protocol redirect

CVSS3: 5.3
debian
3 месяца назад

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that ...

CVSS3: 5.3
github
3 месяца назад

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

CVSS3: 5.3
fstec
3 месяца назад

Уязвимость программного средства для взаимодействия с серверами cURL, связанная с переадресацией URL на ненадежный сайт, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации

EPSS

Процентиль: 7%
0.00026
Низкий

5.3 Medium

CVSS3