Sploitus

CVE-2021-22898

No indexed exploits for CVE-2021-22898 yet

curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

Haxx Curl
≤ 7.76.1
CVSS 3.1
3.1 LOW
EPSS
4.4% (90th percentile)
Weakness
CWE-909, CWE-200
NVD status
Modified
Published
2021-06-11
CVE-2021-22898 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2021-22898 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2021-22898 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.