Lucene search

K
cve[email protected]CVE-2015-3236
HistoryJun 22, 2015 - 7:59 p.m.

CVE-2015-3236

2015-06-2219:59:03
CWE-200
web.nvd.nist.gov
40
curl
libcurl
cve-2015-3236
http
authentication
security
remote attackers
sensitive information

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

9.1 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.0%

cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.

Affected configurations

NVD
Node
haxxcurlMatch7.40.0
OR
haxxcurlMatch7.41.0
OR
haxxcurlMatch7.42.0
OR
haxxcurlMatch7.42.1
OR
haxxlibcurlMatch7.40.0
OR
haxxlibcurlMatch7.41.0
OR
haxxlibcurlMatch7.42.0
OR
haxxlibcurlMatch7.42.1

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

9.1 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.0%