CVE-2021-22876Exposure of Private Personal Information to an Unauthorized Actor in Libcurl

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 69.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1
Latest updateMay 24

Description

curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages8 packages

CVEListV5https/github.com_curl_curl7.1.1 to and including 7.75.0
NVDhaxx/libcurl7.1.17.75.0
Debianhaxx/curl< 7.74.0-1.2+3
Ubuntuhaxx/curl< 7.47.0-1ubuntu2.19+2
NVDsplunk/universal_forwarder8.2.08.2.12+2

Also affects: Debian Linux 9.0, Fedora 32, 33, 34

Patches

🔴Vulnerability Details

4
GHSA
GHSA-jjr6-2g8j-hmwr: curl 72022-05-24
CVEList
CVE-2021-22876: curl 72021-04-01
OSV
CVE-2021-22876: curl 72021-04-01
OSV
curl vulnerabilities2021-03-31

📋Vendor Advisories

4
Ubuntu
curl vulnerability2021-04-07
Red Hat
curl: Leak of authentication credentials in URL via automatic Referer2021-03-31
Ubuntu
curl vulnerabilities2021-03-31
Debian
CVE-2021-22876: curl - curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Pers...2021

💬Community

1
HackerOne
CVE-2021-22876: Automatic referer leaks credentials2021-04-30
CVE-2021-22876 — Haxx Libcurl vulnerability | cvebase