Description
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3085-1 | curl security update |
Debian DSA |
DSA-5197-1 | curl security update |
Ubuntu USN |
USN-5397-1 | curl vulnerabilities |
References
History
Wed, 20 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Brocade
Subscribe
Fabric Operating System
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Haxx
Subscribe
Curl
Subscribe
Netapp
Subscribe
Clustered Data Ontap
Subscribe
H300s
Subscribe
H300s Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Hci Bootstrap Os
Subscribe
Hci Compute Node
Subscribe
Solidfire \& Hci Management Node
Subscribe
Solidfire \& Hci Storage Node
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Splunk
Subscribe
Universal Forwarder
Subscribe
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-11-20T15:23:17.772Z
Reserved: 2022-03-23T00:00:00.000Z
Link: CVE-2022-27776
Updated: 2024-08-03T05:32:59.926Z
Status : Modified
Published: 2022-06-02T14:15:43.713
Modified: 2024-11-21T06:56:09.920
Link: CVE-2022-27776
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Ubuntu USN