CVE-2022-27774: Medium severity haxx curl vulnerability
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27774?
CVE-2022-27774 is an insufficiently protected credentials vulnerability in curl 4.9 to 7.82.0 that could allow an attacker to extract credentials when HTTP(S) redirects are used with authentication.
Which software versions are affected by CVE-2022-27774?
curl versions 4.9 to 7.82.0 are affected by CVE-2022-27774.
What is the severity of CVE-2022-27774?
CVE-2022-27774 has a severity rating of 5.7, which is classified as high.
How can an attacker exploit CVE-2022-27774?
An attacker can exploit CVE-2022-27774 by leveraging HTTP(S) redirects with authentication to extract credentials.
Are there any remedies or patches available for CVE-2022-27774?
Yes, the recommended remedy versions for CVE-2022-27774 are: curl 7.64.0-4+deb10u7, curl 7.74.0-1.3+deb11u9, curl 7.74.0-1.3+deb11u10, curl 7.88.1-10+deb12u3, curl 7.88.1-10+deb12u4, and curl 8.4.0-2.