Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-14524

Опубликовано: 08 янв. 2026
Источник: ubuntu
Приоритет: low
CVSS3: 5.3

Описание

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

РелизСтатусПримечание
devel

needed

esm-infra-legacy/trusty

needed

esm-infra/bionic

needed

esm-infra/focal

needed

esm-infra/xenial

needed

jammy

needed

noble

needed

plucky

ignored

end of life, was needed
questing

needed

upstream

pending

8.18.0-1

Показывать по

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 месяца назад

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

CVSS3: 5.3
debian
около 1 месяца назад

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that ...

CVSS3: 5.3
redos
10 дней назад

Уязвимость curl

CVSS3: 5.3
github
около 1 месяца назад

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

suse-cvrf
около 1 месяца назад

Security update for curl

5.3 Medium

CVSS3