Логотип exploitDog
bind:CVE-2021-22923
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-22923

Количество 14

Количество 14

ubuntu логотип

CVE-2021-22923

почти 4 года назад

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2021-22923

почти 4 года назад

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2021-22923

почти 4 года назад

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-22923

почти 4 года назад

When curl is instructed to get content using the metalink feature, and ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-89qw-6g6w-269q

около 3 лет назад

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2022-02170

почти 4 года назад

Уязвимость программного средства для взаимодействия с серверами CURL, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2021-3582

почти 4 года назад

ELSA-2021-3582: curl security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2439-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1088-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2462-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2440-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2439-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2425-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:14768-1

почти 4 года назад

Security update for curl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-22923

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2021-22923

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

CVSS3: 5.7
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-22923

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-22923

When curl is instructed to get content using the metalink feature, and ...

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-89qw-6g6w-269q

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2022-02170

Уязвимость программного средства для взаимодействия с серверами CURL, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.3
0%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2021-3582

ELSA-2021-3582: curl security update (MODERATE)

почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:2439-1

Security update for curl

почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1088-1

Security update for curl

почти 4 года назад
suse-cvrf логотип
SUSE-SU-2021:2462-1

Security update for curl

почти 4 года назад
suse-cvrf логотип
SUSE-SU-2021:2440-1

Security update for curl

почти 4 года назад
suse-cvrf логотип
SUSE-SU-2021:2439-1

Security update for curl

почти 4 года назад
suse-cvrf логотип
SUSE-SU-2021:2425-1

Security update for curl

почти 4 года назад
suse-cvrf логотип
SUSE-SU-2021:14768-1

Security update for curl

почти 4 года назад

Уязвимостей на страницу