3.4

CVE-2025-0167

Exploit

netrc and default credential leak

When asked to use a `.netrc` file for credentials **and** to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.

This flaw only manifests itself if the netrc file has a `default` entry that
omits both login and password. A rare circumstance.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haxx ≫ Curl Version >= 7.76.0 < 8.12.0
Netapp ≫ Element Software Version -
Netapp ≫ Ontap Version 9
Netapp ≫ Ontap Tools Version 9 SwPlatform vmware_vsphere
Netapp ≫ Bootstrap Os Version -
   Netapp ≫ Hci Compute Node Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H410c Firmware Version -
   Netapp ≫ H410c Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H610c Firmware Version -
   Netapp ≫ H610c Version -
Netapp ≫ H610s Firmware Version -
   Netapp ≫ H610s Version -
Netapp ≫ H615c Firmware Version -
   Netapp ≫ H615c Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.488
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 3.4 1.6 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://curl.se/docs/CVE-2025-0167.html
Vendor Advisory
https://curl.se/docs/CVE-2025-0167.json
Vendor Advisory
https://hackerone.com/reports/2917232
Third Party Advisory
Exploit
Issue Tracking
https://security.netapp.com/advisory/ntap-20250306-0008/
Third Party Advisory