ZeroHour

CVE-2024-11053

PoC
CVSS 3.1
3.4 low
EPSS
1%p71
Published
()
Modified
Description

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

Vendors
haxxnetapp
Products
curl, ontap, ontap select deploy administration utility, h610c firmware, h610s firmware, h615c firmware, h700s firmware, bootstrap os, h300s firmware, h410s firmware, h500s firmware
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.