ZeroHour

CVE-2022-27776

PoC
CVSS 3.1
6.5 medium
EPSS
4%p89
Published
()
Modified
Description

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

Vendors
haxxfedoraprojectdebiannetappbrocadesplunk
Products
curl, fedora, debian linux, hci bootstrap os, clustered data ontap, solidfire \& hci management node, solidfire \& hci storage node, fabric operating system, h300s firmware, h500s firmware, h700s firmware, h410s firmware
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.