cbcvebase.
CVE-2022-27776
published 2022-06-02

CVE-2022-27776: A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host…

PriorityP336medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
3.78%
89.5th percentile
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debiancurl< curl 7.83.0-1 (bookworm)curl 7.83.0-1 (bookworm)
debiandebian_linux——
debiandebian_linux——
fedoraprojectfedora——
fedoraprojectfedora——
guzzlehttpguzzle>= 0 < 6.5.86.5.8
guzzlehttpguzzle>= 7.0.0 < 7.4.57.4.5
haxxcurl< 7.83.07.83.0
haxxcurl>= 0 < 7.74.0-1.3+deb11u27.74.0-1.3+deb11u2
haxxcurl>= 0 < 7.83.0-17.83.0-1
haxxcurl>= 0 < 7.83.0-17.83.0-1
haxxcurl>= 0 < 7.83.0-17.83.0-1
haxxcurl>= 0 < 7.58.0-2ubuntu3.177.58.0-2ubuntu3.17
haxxcurl>= 0 < 7.68.0-1ubuntu2.107.68.0-1ubuntu2.10
haxxcurl>= 0 < 7.81.0-1ubuntu1.17.81.0-1ubuntu1.1
httpsgithub.com_curl_curl——
msrcwindows_10_version_1809_for_32-bit_systems——
msrcwindows_10_version_1809_for_arm64-based_systems——
msrcwindows_10_version_1809_for_x64-based_systems——
msrcwindows_10_version_20h2_for_32-bit_systems——
msrcwindows_10_version_20h2_for_arm64-based_systems——
msrcwindows_10_version_21h1_for_32-bit_systems——
msrcwindows_10_version_21h1_for_arm64-based_systems——
msrcwindows_10_version_21h1_for_x64-based_systems——
msrcwindows_10_version_21h2_for_32-bit_systems——

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_ubuntu8.1HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.