cbcvebase.
CVE-2022-27776
published 2022-06-02

CVE-2022-27776: A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host…

PriorityP335medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
3.43%
87.4th percentile
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debiancurl< curl 7.83.0-1 (bookworm)curl 7.83.0-1 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
guzzlehttpguzzle>= 0 < 6.5.86.5.8
guzzlehttpguzzle>= 7.0.0 < 7.4.57.4.5
haxxcurl< 7.83.07.83.0
haxxcurl>= 0 < 7.74.0-1.3+deb11u27.74.0-1.3+deb11u2
haxxcurl>= 0 < 7.83.0-17.83.0-1
haxxcurl>= 0 < 7.83.0-17.83.0-1
haxxcurl>= 0 < 7.83.0-17.83.0-1
haxxcurl>= 0 < 7.58.0-2ubuntu3.177.58.0-2ubuntu3.17
haxxcurl>= 0 < 7.68.0-1ubuntu2.107.68.0-1ubuntu2.10
haxxcurl>= 0 < 7.81.0-1ubuntu1.17.81.0-1ubuntu1.1
httpsgithub.com_curl_curl
msrcwindows_10_version_1809_for_32-bit_systems
msrcwindows_10_version_1809_for_arm64-based_systems
msrcwindows_10_version_1809_for_x64-based_systems
msrcwindows_10_version_20h2_for_32-bit_systems
msrcwindows_10_version_20h2_for_arm64-based_systems
msrcwindows_10_version_21h1_for_32-bit_systems
msrcwindows_10_version_21h1_for_arm64-based_systems
msrcwindows_10_version_21h1_for_x64-based_systems
msrcwindows_10_version_21h2_for_32-bit_systems

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_ubuntu8.1HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.