CVE-2022-27774
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Linuxmint, Red Hat, Red Os, Rocky Linux
- Haxx Curl
- ≤ 7.82.0
- CVSS 3.1
- 5.7 MEDIUM
- EPSS
- 1.7% (75th percentile)
- Weakness
- CWE-522
- NVD status
- Modified
- Published
- 2022-06-01
CVE-2022-27774 at NVD
No indexed exploits for CVE-2022-27774 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-27774 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.