Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-22876
HistoryMar 31, 2021 - 12:00 a.m.

CVE-2021-22876

2021-03-3100:00:00
ubuntu.com
ubuntu.com
12

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.009 Low

EPSS

Percentile

83.1%

curl 7.1.1 to and including 7.75.0 is vulnerable to an “Exposure of Private
Personal Information to an Unauthorized Actor” by leaking credentials in
the HTTP Referer: header. libcurl does not strip off user credentials from
the URL when automatically populating the Referer: HTTP request header
field in outgoing HTTP requests, and therefore risks leaking sensitive data
to the server that is the target of the second HTTP request.

Notes

Author Note
alexmurray affects curl versions between 7.1.1 and 7.75.0
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchcurl< 7.58.0-2ubuntu3.13UNKNOWN
ubuntu20.04noarchcurl< 7.68.0-1ubuntu2.5UNKNOWN
ubuntu20.10noarchcurl< 7.68.0-1ubuntu4.3UNKNOWN
ubuntu21.04noarchcurl< 7.74.0-1ubuntu2UNKNOWN
ubuntu14.04noarchcurl< 7.35.0-1ubuntu2.20+esm7UNKNOWN
ubuntu16.04noarchcurl< 7.47.0-1ubuntu2.19UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.009 Low

EPSS

Percentile

83.1%