Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Required
Privileges Required
Low
Attack Vector
Network
0

CVE-2022-27774

Disclosure Date: June 02, 2022
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
5.7 Medium
Impact Score:
3.6
Exploitability Score:
2.1
Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
Required
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
None
Availability (A):
None

General Information

Vendors

  • brocade,
  • debian,
  • haxx,
  • netapp,
  • splunk

Products

  • clustered data ontap -,
  • curl,
  • debian linux 10.0,
  • debian linux 11.0,
  • fabric operating system -,
  • h300s firmware -,
  • h410s firmware -,
  • h500s firmware -,
  • h700s firmware -,
  • hci bootstrap os -,
  • solidfire & hci management node -,
  • solidfire & hci storage node -,
  • universal forwarder,
  • universal forwarder 9.1.0
Technical Analysis