3.4

CVE-2024-11053

Exploit

netrc and redirect credential leak

When asked to both use a `.netrc` file for credentials and to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.

This flaw only manifests itself if the netrc file has an entry that matches
the redirect target hostname but the entry either omits just the password or
omits both login and password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haxx ≫ Curl Version >= 7.76.0 < 8.11.1
Netapp ≫ Ontap Version 9
Netapp ≫ H610c Firmware Version -
   Netapp ≫ H610c Version -
Netapp ≫ H610s Firmware Version -
   Netapp ≫ H610s Version -
Netapp ≫ H615c Firmware Version -
   Netapp ≫ H615c Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ Bootstrap Os Version -
   Netapp ≫ Hci Compute Node Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.38% 0.688
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 3.4 1.6 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://curl.se/docs/CVE-2024-11053.html
Vendor Advisory
https://curl.se/docs/CVE-2024-11053.json
Vendor Advisory
https://hackerone.com/reports/2829063
Third Party Advisory
Exploit
Issue Tracking
http://www.openwall.com/lists/oss-security/2024/12/11/1
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20250124-0012/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20250131-0003/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20250131-0004/