Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39329
HistoryFeb 18, 2023 - 5:20 a.m.

Information Disclosure

2023-02-1805:20:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22
curl
hsts
https
cleartext transmission
information disclosure
software

EPSS

0.001

Percentile

30.8%

curl is vulnerable to Information Disclosure. curls HSTS support allows the use of HTTPS instead of HTTP but the HSTS could fail when used subsequently on the same command line leading to Cleartext Transmission which allows an attacker to gain access to sensitive information.