CVE-2022-27774
Last modified
CVE-2022-27774 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.. EPSS estimates a 1.59% chance of exploitation in the next 30 days.
Description
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Haxx | Curl | >= 4.9, <= 7.82.0 |
| Debian | Debian Linux | 10.0 |
| Debian | Debian Linux | 11.0 |
| Netapp | Hci Bootstrap Os | All versions |
| Netapp | Clustered Data Ontap | All versions |
| Netapp | Solidfire \& Hci Management Node | All versions |
| Netapp | Solidfire \& Hci Storage Node | All versions |
| Brocade | Fabric Operating System | All versions |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H410s Firmware | All versions |
| Splunk | Universal Forwarder | >= 8.2.0, < 8.2.12 |
| Splunk | Universal Forwarder | >= 9.0.0, < 9.0.6 |
| Splunk | Universal Forwarder | 9.1.0 |
References
- https://hackerone.com/reports/1543773Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/01/msg00028.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202212-01Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220609-0008/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5197Third Party Advisory
- https://hackerone.com/reports/1543773Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/01/msg00028.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202212-01Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220609-0008/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5197Third Party Advisory
- https://hackerone.com/reports/1543773Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-27774?
How severe is CVE-2022-27774?
How do I fix CVE-2022-27774?
Are you affected by CVE-2022-27774?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
