When asked to use a `.netrc` file for credentials **and** to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has a `default` entry that
omits both login and password. A rare circumstance.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Mar 2025 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 06 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 05 Feb 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance. | |
Title | netrc and default credential leak | |
References |
|

Status: PUBLISHED
Assigner: curl
Published:
Updated: 2025-03-07T00:10:48.290Z
Reserved: 2024-12-31T23:07:29.650Z
Link: CVE-2025-0167

Updated: 2025-03-07T00:10:48.290Z

Status : Awaiting Analysis
Published: 2025-02-05T10:15:22.710
Modified: 2025-03-07T01:15:12.110
Link: CVE-2025-0167

No data.