Описание
Successfully using libcurl to do a transfer to a specific HTTP origin (hostA) with Digest authentication and then changing the origin to a different one (hostB) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the Authorization: header field meant for hostA, to hostB.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needed | |
| esm-infra-legacy/trusty | ignored | changes too intrusive |
| esm-infra-legacy/xenial | ignored | changes too intrusive |
| esm-infra/bionic | ignored | changes too intrusive |
| esm-infra/focal | ignored | changes too intrusive |
| jammy | ignored | changes too intrusive |
| noble | ignored | changes too intrusive |
| questing | ignored | end of life, was ignored [changes too intrusive] |
| resolute | ignored | changes too intrusive |
| upstream | pending | 8.21.0 |
Показывать по
9.8 Critical
CVSS3
Связанные уязвимости
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.
Successfully using libcurl to do a transfer to a specific HTTP origin ...
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.
9.8 Critical
CVSS3