Description
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer
performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP,
POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new
target host.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 13 | | =8.14.1-2 || =8.14.1-2+deb13u1 || =8.14.1-2+deb13u2 || =8.14.1-2+deb13u2~bpo13+1 || =8.14.1-2+deb13u3 || >=0 <8.14.1-2+deb13u4 | 8.14.1-2+deb13u4 |
 debian 14 | | =8.14.1-2 || =8.14.1-2+exp1 || =8.15.0-1 || =8.15.0-1~bpo13+1 || =8.15.0-1~exp1 || =8.15.0~rc1-1exp1 || =8.15.0~rc2-1~exp1 || =8.15.0~rc3-1~exp1 || =8.16.0-1 || =8.16.0-1+exp1 || =8.16.0-1~bpo13+1 || =8.16.0-2 || =8.16.0-3 || =8.16.0-4 || =8.16.0-4~bpo13+1 || =8.16.0~rc1-1~exp1 || =8.16.0~rc2-1 || =8.16.0~rc2-2 || =8.16.0~rc3-1 || =8.17.0-1 || =8.17.0-2 || =8.17.0-3 || =8.17.0~rc1-1~exp1 || =8.17.0~rc2-1 || =8.17.0~rc3-1 || =8.18.0~rc1-1+exp1 || >=0 <8.18.0~rc2-1 | 8.18.0~rc2-1 |
 debian 12 | | =7.88.1-10 || =7.88.1-10+deb12u1 || =7.88.1-10+deb12u11 || =7.88.1-10+deb12u12 || =7.88.1-10+deb12u13 || =7.88.1-10+deb12u14 || =7.88.1-10+deb12u1~bpo11+1 || =7.88.1-10+deb12u2 || =7.88.1-10+deb12u3 || =7.88.1-10+deb12u3~bpo11+1 || =7.88.1-10+deb12u4 || =7.88.1-10+deb12u5 || =7.88.1-10+deb12u5~bpo11+1 || =7.88.1-10+deb12u6 || =7.88.1-10+deb12u6~bpo11+1 || =7.88.1-10+deb12u7 || =7.88.1-10+deb12u8 || =7.88.1-10+deb12u9 || >=0 <7.88.1-10+deb12u15 | 7.88.1-10+deb12u15 |
 rpm rhel10 | | - | - |
 rpm rhel6 | | - | - |
 rpm rhel7 | | - | - |
 rpm rhel8 | | - | - |
 rpm rhel9 | | - | - |
 rpm rhel10 | | - | - |
 rpm rhel9 | | - | - |