← voltar
CVE-2024-11053low

netrc and redirect credential leak

8Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 3.4epss 1.3%
probabilidade de exploração
1.3%top 30% das CVEs
exploração observada
nãonenhuma fonte reporta
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Produtos afetados
curl · curl