Sensitive information sent insecurely In curl
Description
When asked to use a .netrc file for credentials and to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has a default entry that
omits both login and password. A rare circumstance.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 8.12.0+git20250209.89ed161+ds-1 | ||
debian 14 | 8.12.0+git20250209.89ed161+ds-1 | ||
alpine v3.18 | 8.12.0-r0 | ||
alpine v3.19 | 8.12.0-r0 | ||
alpine v3.20 | 8.12.0-r0 | ||
alpine v3.21 | 8.12.0-r0 | ||
alpine v3.22 | 8.12.0-r0 | ||
debian 12 | 7.88.1-10+deb12u11 | ||
alpine v3.23 | 8.12.0-r0 | ||
alpine v3.24 | 8.12.0-r0 |
Aliases
1. 2. 3. 4. 5. 6. 7.