CVE-2020-8169Sensitive Information Exposure in Siemens Sinec Infrastructure Network Services

Severity
7.5HIGHNVD
EPSS
0.1%
top 84.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 14
Latest updateMay 24

Description

curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages7 packages

Debianhaxx/curl< 7.72.0-1+3
Ubuntuhaxx/curl< 7.47.0-1ubuntu2.15+3
NVDhaxx/curl7.62.07.70.0
CVEListV5https/github.com_curl_curllibcurl 7.62.0 to and including 7.70.0

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-whwh-vhp2-pj62: curl 72022-05-24
OSV
CVE-2020-8169: curl 72020-12-14
CVEList
CVE-2020-8169: curl 72020-12-14
OSV
curl vulnerabilities2020-06-24

📋Vendor Advisories

4
Microsoft
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).2020-12-08
Red Hat
libcurl: partial password leak over DNS on HTTP redirect2020-06-24
Ubuntu
curl vulnerabilities2020-06-24
Debian
CVE-2020-8169: curl - curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerabil...2020

💬Community

5
HackerOne
CVE-2020-8169: Partial password leak over DNS on HTTP redirect2020-12-05
Bugzilla
CVE-2020-8169 flickcurl: libcurl: partial password leak over DNS on HTTP redirect [fedora-all]2020-06-26
Bugzilla
CVE-2020-8169 mingw-curl: libcurl: partial password leak over DNS on HTTP redirect [fedora-all]2020-06-26
Bugzilla
CVE-2020-8169 curl: libcurl: partial password leak over DNS on HTTP redirect [fedora-all]2020-06-26
Bugzilla
CVE-2020-8169 libcurl: partial password leak over DNS on HTTP redirect2020-06-17
CVE-2020-8169 — Sensitive Information Exposure | cvebase