Количество 13
Количество 13
GHSA-jjr6-2g8j-hmwr
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.

CVE-2021-22876
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.

CVE-2021-22876
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.

CVE-2021-22876
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.
CVE-2021-22876
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Pr ...

SUSE-SU-2021:14707-1
Security update for curl

SUSE-SU-2021:1396-1
Security update for curl

BDU:2021-05241
Уязвимость программного средства для взаимодействия с серверами CURL, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

openSUSE-SU-2021:0510-1
Security update for curl

SUSE-SU-2021:1809-1
Security update for curl

SUSE-SU-2021:1006-1
Security update for curl
ELSA-2021-4511
ELSA-2021-4511: curl security and bug fix update (MODERATE)

SUSE-SU-2021:1786-1
Security update for curl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-jjr6-2g8j-hmwr curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
![]() | CVE-2021-22876 curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request. | CVSS3: 5.3 | 0% Низкий | около 4 лет назад |
![]() | CVE-2021-22876 curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request. | CVSS3: 3.7 | 0% Низкий | около 4 лет назад |
![]() | CVE-2021-22876 curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request. | CVSS3: 5.3 | 0% Низкий | около 4 лет назад |
CVE-2021-22876 curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Pr ... | CVSS3: 5.3 | 0% Низкий | около 4 лет назад | |
![]() | SUSE-SU-2021:14707-1 Security update for curl | 0% Низкий | около 4 лет назад | |
![]() | SUSE-SU-2021:1396-1 Security update for curl | 0% Низкий | около 4 лет назад | |
![]() | BDU:2021-05241 Уязвимость программного средства для взаимодействия с серверами CURL, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным | CVSS3: 5.3 | 0% Низкий | больше 4 лет назад |
![]() | openSUSE-SU-2021:0510-1 Security update for curl | около 4 лет назад | ||
![]() | SUSE-SU-2021:1809-1 Security update for curl | около 4 лет назад | ||
![]() | SUSE-SU-2021:1006-1 Security update for curl | около 4 лет назад | ||
ELSA-2021-4511 ELSA-2021-4511: curl security and bug fix update (MODERATE) | больше 3 лет назад | |||
![]() | SUSE-SU-2021:1786-1 Security update for curl | около 4 лет назад |
Уязвимостей на страницу