CVE-2022-27776

MEDIUM

curl < 7.83.0 - Credential Leak via HTTP Redirect to Different Port

Title source: llm
STIX 2.1

Description

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

Scores

CVSS v3 6.5
EPSS 0.0068
EPSS Percentile 71.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (16)
brocade/fabric_operating_system
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 36
fedoraproject/fedora 37
haxx/curl < 7.83.0
netapp/clustered_data_ontap
netapp/h300s_firmware
netapp/h410s_firmware
netapp/h500s_firmware
... and 6 more
Published Jun 02, 2022
Tracked Since Feb 18, 2026