CVE-2025-0167
CVE-2025-0167
Título es
CVE-2025-0167
Mié, 05/02/2025 – 10:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-0167
Descripción en
When asked to use a `.netrc` file for credentials **and** to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has a `default` entry that
omits both login and password. A rare circumstance.
05/02/2025
05/02/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off