An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2022-06-01T00:00:00

Updated: 2024-08-03T05:32:59.946Z

Reserved: 2022-03-23T00:00:00

Link: CVE-2022-27774

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-02T14:15:43.317

Modified: 2024-03-27T15:02:31.430

Link: CVE-2022-27774

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-04-27T06:00:00Z

Links: CVE-2022-27774 - Bugzilla