netrc and redirect credential leak
8Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 3.4epss 1.3%
probabilidade de exploração
1.3%top 30% das CVEs
exploração observada
nãonenhuma fonte reporta
When asked to both use a `.netrc` file for credentials and to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has an entry that matches
the redirect target hostname but the entry either omits just the password or
omits both login and password.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Produtos afetados
curl · curlReferências
https://curl.se/docs/CVE-2024-11053.htmlhttps://curl.se/docs/CVE-2024-11053.jsonhttps://hackerone.com/reports/2829063https://security.netapp.com/advisory/ntap-20250124-0012/https://security.netapp.com/advisory/ntap-20250131-0003/https://security.netapp.com/advisory/ntap-20250131-0004/http://www.openwall.com/lists/oss-security/2024/12/11/1