Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Network
0

CVE-2021-22876

Disclosure Date: April 01, 2021
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

curl 7.1.1 to and including 7.75.0 is vulnerable to an “Exposure of Private Personal Information to an Unauthorized Actor” by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
5.3 Medium
Impact Score:
1.4
Exploitability Score:
3.9
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
Low
Integrity (I):
None
Availability (A):
None

General Information

Vendors

  • broadcom,
  • debian,
  • fedoraproject,
  • haxx,
  • netapp,
  • oracle,
  • siemens,
  • splunk

Products

  • communications billing and revenue management 12.0.0.3.0,
  • debian linux 9.0,
  • essbase 21.2,
  • fabric operating system -,
  • fedora 32,
  • fedora 33,
  • fedora 34,
  • hci compute node -,
  • hci management node -,
  • hci storage node -,
  • libcurl,
  • sinec infrastructure network services,
  • solidfire -,
  • universal forwarder,
  • universal forwarder 9.1.0
Technical Analysis