Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17

Количество 17

github логотип

GHSA-h288-5fq8-5pfw

больше 1 года назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2024-11053

больше 1 года назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 3.4
EPSS: Низкий
redhat логотип

CVE-2024-11053

больше 1 года назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-11053

больше 1 года назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 3.4
EPSS: Низкий
msrc логотип

CVE-2024-11053

больше 1 года назад

netrc and redirect credential leak

CVSS3: 3.4
EPSS: Низкий
debian логотип

CVE-2024-11053

больше 1 года назад

When asked to both use a `.netrc` file for credentials and to follow H ...

CVSS3: 3.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4359-1

больше 1 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4288-1

больше 1 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4284-2

больше 1 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4284-1

больше 1 года назад

Security update for curl

EPSS: Низкий
fstec логотип

BDU:2024-11106

больше 1 года назад

Уязвимость обработчика netrc-файлов утилиты командной строки cURL, позволяющая нарушителю получить доступ к учётным данным

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20250424-25

больше 1 года назад

Множественные уязвимости libcurl

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20250424-05

больше 1 года назад

Множественные уязвимости curl

CVSS3: 9.1
EPSS: Низкий
rocky логотип

RLSA-2025:1673

больше 1 года назад

Important: mysql:8.0 security update

EPSS: Низкий
rocky логотип

RLSA-2025:1671

больше 1 года назад

Important: mysql security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-1673

больше 1 года назад

ELSA-2025-1673: mysql:8.0 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-1671

больше 1 года назад

ELSA-2025-1671: mysql security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-h288-5fq8-5pfw

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 9.1
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 3.4
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 5.9
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 3.4
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-11053

netrc and redirect credential leak

CVSS3: 3.4
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow H ...

CVSS3: 3.4
1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:4359-1

Security update for curl

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:4288-1

Security update for curl

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:4284-2

Security update for curl

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:4284-1

Security update for curl

1%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-11106

Уязвимость обработчика netrc-файлов утилиты командной строки cURL, позволяющая нарушителю получить доступ к учётным данным

CVSS3: 9.1
1%
Низкий
больше 1 года назад
redos логотип
ROS-20250424-25

Множественные уязвимости libcurl

CVSS3: 9.1
больше 1 года назад
redos логотип
ROS-20250424-05

Множественные уязвимости curl

CVSS3: 9.1
больше 1 года назад
rocky логотип
RLSA-2025:1673

Important: mysql:8.0 security update

больше 1 года назад
rocky логотип
RLSA-2025:1671

Important: mysql security update

больше 1 года назад
oracle-oval логотип
ELSA-2025-1673

ELSA-2025-1673: mysql:8.0 security update (IMPORTANT)

больше 1 года назад
oracle-oval логотип
ELSA-2025-1671

ELSA-2025-1671: mysql security update (IMPORTANT)

больше 1 года назад

Уязвимостей на страницу