Логотип exploitDog
bind:"GHSA-h288-5fq8-5pfw" OR bind:"CVE-2024-11053"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-h288-5fq8-5pfw" OR bind:"CVE-2024-11053"

Количество 14

Количество 14

github логотип

GHSA-h288-5fq8-5pfw

6 месяцев назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2024-11053

6 месяцев назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 3.4
EPSS: Низкий
redhat логотип

CVE-2024-11053

6 месяцев назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-11053

6 месяцев назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 3.4
EPSS: Низкий
msrc логотип

CVE-2024-11053

5 месяцев назад

CVSS3: 3.4
EPSS: Низкий
debian логотип

CVE-2024-11053

6 месяцев назад

When asked to both use a `.netrc` file for credentials and to follow H ...

CVSS3: 3.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4359-1

6 месяцев назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4288-1

6 месяцев назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4284-2

6 месяцев назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4284-1

6 месяцев назад

Security update for curl

EPSS: Низкий
fstec логотип

BDU:2024-11106

7 месяцев назад

Уязвимость обработчика netrc-файлов утилиты командной строки cURL, позволяющая нарушителю получить доступ к учётным данным

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20250424-05

около 2 месяцев назад

Множественные уязвимости curl

CVSS3: 9.1
EPSS: Низкий
oracle-oval логотип

ELSA-2025-1673

4 месяца назад

ELSA-2025-1673: mysql:8.0 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-1671

4 месяца назад

ELSA-2025-1671: mysql security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-h288-5fq8-5pfw

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 9.1
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 3.4
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 5.9
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS3: 3.4
0%
Низкий
6 месяцев назад
msrc логотип
CVSS3: 3.4
0%
Низкий
5 месяцев назад
debian логотип
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow H ...

CVSS3: 3.4
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:4359-1

Security update for curl

0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:4288-1

Security update for curl

0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:4284-2

Security update for curl

0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:4284-1

Security update for curl

0%
Низкий
6 месяцев назад
fstec логотип
BDU:2024-11106

Уязвимость обработчика netrc-файлов утилиты командной строки cURL, позволяющая нарушителю получить доступ к учётным данным

CVSS3: 9.1
0%
Низкий
7 месяцев назад
redos логотип
ROS-20250424-05

Множественные уязвимости curl

CVSS3: 9.1
около 2 месяцев назад
oracle-oval логотип
ELSA-2025-1673

ELSA-2025-1673: mysql:8.0 security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2025-1671

ELSA-2025-1671: mysql security update (IMPORTANT)

4 месяца назад

Уязвимостей на страницу