CVE-2022-27776

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
References
Link Resource
https://hackerone.com/reports/1547048 Exploit Third Party Advisory
https://security.netapp.com/advisory/ntap-20220609-0008/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*

Information

Published : 2022-06-02 14:15

Updated : 2022-06-14 17:53


NVD link : CVE-2022-27776

Mitre link : CVE-2022-27776


JSON object : View

Products Affected

haxx

  • curl
CWE
CWE-522

Insufficiently Protected Credentials