CVE-2022-27776

MEDIUM

Haxx Curl < 7.83.0 - Insufficiently Protected Credentials

Title source: rule

Description

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

Scores

CVSS v3 6.5
EPSS 0.0068
EPSS Percentile 71.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (16)

haxx/curl < 7.83.0
fedoraproject/fedora
fedoraproject/fedora
debian/debian_linux
debian/debian_linux
netapp/hci_bootstrap_os
netapp/clustered_data_ontap
netapp/solidfire_\&_hci_management_node
netapp/solidfire_\&_hci_storage_node
brocade/fabric_operating_system
netapp/h300s_firmware
netapp/h500s_firmware
netapp/h700s_firmware
netapp/h410s_firmware
splunk/universal_forwarder < 8.2.12
... and 1 more

Timeline

Published Jun 02, 2022
Tracked Since Feb 18, 2026