Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39330
HistoryFeb 18, 2023 - 5:22 a.m.

Information Disclosure

2023-02-1805:22:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20
curl
vulnerability
information disclosure
hsts
https
cleartext transmission
attacker

0.001 Low

EPSS

Percentile

44.9%

curl is vulnerable to Information Disclosure. curls HSTS support allows the use of HTTPS instead of HTTP but the HSTS could fail when used subsequently on the same command line leading to Cleartext Transmission which allows an attacker to gain sensitive information of the system.