A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
References
| Link | Resource |
|---|---|
| https://hackerone.com/reports/1547048 | Exploit Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20220609-0008/ | Third Party Advisory |
Configurations
Information
Published : 2022-06-02 14:15
Updated : 2022-06-14 17:53
NVD link : CVE-2022-27776
Mitre link : CVE-2022-27776
JSON object : View
Products Affected
haxx
- curl
CWE
CWE-522
Insufficiently Protected Credentials
