Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 18

Количество 18

ubuntu логотип

CVE-2024-11053

почти 2 года назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 3.4
EPSS: Низкий
redhat логотип

CVE-2024-11053

почти 2 года назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-11053

почти 2 года назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 3.4
EPSS: Низкий
msrc логотип

CVE-2024-11053

больше 1 года назад

netrc and redirect credential leak

CVSS3: 3.4
EPSS: Низкий
debian логотип

CVE-2024-11053

почти 2 года назад

When asked to both use a `.netrc` file for credentials and to follow H ...

CVSS3: 3.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4359-1

больше 1 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4288-1

почти 2 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4284-2

больше 1 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4284-1

больше 1 года назад

Security update for curl

EPSS: Низкий
github логотип

GHSA-h288-5fq8-5pfw

почти 2 года назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2024-11106

почти 2 года назад

Уязвимость обработчика netrc-файлов утилиты командной строки cURL, позволяющая нарушителю получить доступ к учётным данным

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20260310-80-0003

6 месяцев назад

Уязвимость curl

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20250424-25

больше 1 года назад

Множественные уязвимости libcurl

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20250424-05

больше 1 года назад

Множественные уязвимости curl

CVSS3: 9.1
EPSS: Низкий
rocky логотип

RLSA-2025:1673

больше 1 года назад

Important: mysql:8.0 security update

EPSS: Низкий
rocky логотип

RLSA-2025:1671

больше 1 года назад

Important: mysql security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-1673

больше 1 года назад

ELSA-2025-1673: mysql:8.0 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-1671

больше 1 года назад

ELSA-2025-1671: mysql security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 3.4
1%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 5.9
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 3.4
1%
Низкий
почти 2 года назад
msrc логотип
CVE-2024-11053

netrc and redirect credential leak

CVSS3: 3.4
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow H ...

CVSS3: 3.4
1%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:4359-1

Security update for curl

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:4288-1

Security update for curl

1%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:4284-2

Security update for curl

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:4284-1

Security update for curl

1%
Низкий
больше 1 года назад
github логотип
GHSA-h288-5fq8-5pfw

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 9.1
1%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-11106

Уязвимость обработчика netrc-файлов утилиты командной строки cURL, позволяющая нарушителю получить доступ к учётным данным

CVSS3: 9.1
1%
Низкий
почти 2 года назад
redos логотип
ROS-20260310-80-0003

Уязвимость curl

CVSS3: 9.1
1%
Низкий
6 месяцев назад
redos логотип
ROS-20250424-25

Множественные уязвимости libcurl

CVSS3: 9.1
больше 1 года назад
redos логотип
ROS-20250424-05

Множественные уязвимости curl

CVSS3: 9.1
больше 1 года назад
rocky логотип
RLSA-2025:1673

Important: mysql:8.0 security update

больше 1 года назад
rocky логотип
RLSA-2025:1671

Important: mysql security update

больше 1 года назад
oracle-oval логотип
ELSA-2025-1673

ELSA-2025-1673: mysql:8.0 security update (IMPORTANT)

больше 1 года назад
oracle-oval логотип
ELSA-2025-1671

ELSA-2025-1671: mysql security update (IMPORTANT)

больше 1 года назад

Уязвимостей на страницу