CVE-2020-8169
HIGHcurl 7.62.0-7.70.0 - Information Disclosure via Password Leak
Title source: llmDescription
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
References (5)
Core 5
Core References
Exploit, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/874778
Vendor Advisory x_refsource_misc
https://curl.se/docs/CVE-2020-8169.html
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2021/dsa-4881
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-200951.pdf
Patch, Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
Scores
CVSS v3
7.5
EPSS
0.0008
EPSS Percentile
24.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (6)
debian/debian_linux
10.0
haxx/curl
7.62.0 - 7.70.0
siemens/simatic_tim_1531_irc_firmware
< 2.2
siemens/sinec_infrastructure_network_services
< 1.0.1.1
splunk/universal_forwarder
9.1.0
splunk/universal_forwarder
8.2.0 - 8.2.12
Published
Dec 14, 2020
Tracked Since
Feb 18, 2026