CVE-2021-22876

Description

curl 7.1.1 to and including 7.75.0 is vulnerable to an Exposure of Private Personal Information to an Unauthorized Actor by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.068

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-22876,CVE-2021-22890,CVE-2021-22924 are affected in Curl For Windows 7.75.0Windows
Vulnerabilities CVE-2021-22890,CVE-2021-22876 are fixed in Curl For Windows 7.76.0Windows
curl security update(DSA-4881-1) curl_7.64.0-4+deb10u2_i386.debLinux
curl security update(DSA-4881-1) curl_7.64.0-4+deb10u2_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) curl_7.68.0-1ubuntu2.5_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) curl_7.68.0-1ubuntu2.5_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) curl_7.68.0-1ubuntu4.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) curl_7.68.0-1ubuntu4.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) curl_7.47.0-1ubuntu2.19_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) curl_7.47.0-1ubuntu2.19_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) curl_7.58.0-2ubuntu3.13_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) curl_7.58.0-2ubuntu3.13_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3_7.47.0-1ubuntu2.19_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3_7.47.0-1ubuntu2.19_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl4_7.68.0-1ubuntu2.5_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl4_7.68.0-1ubuntu2.5_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl4_7.68.0-1ubuntu4.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl4_7.68.0-1ubuntu4.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl4_7.58.0-2ubuntu3.13_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl4_7.58.0-2ubuntu3.13_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-nss_7.68.0-1ubuntu2.5_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-nss_7.68.0-1ubuntu2.5_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-nss_7.68.0-1ubuntu4.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-nss_7.68.0-1ubuntu4.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-nss_7.47.0-1ubuntu2.19_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-nss_7.47.0-1ubuntu2.19_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-nss_7.58.0-2ubuntu3.13_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-nss_7.58.0-2ubuntu3.13_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-gnutls_7.68.0-1ubuntu2.5_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-gnutls_7.68.0-1ubuntu2.5_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-gnutls_7.68.0-1ubuntu4.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-gnutls_7.68.0-1ubuntu4.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-gnutls_7.47.0-1ubuntu2.19_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-gnutls_7.47.0-1ubuntu2.19_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-gnutls_7.58.0-2ubuntu3.13_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-4898-1) libcurl3-gnutls_7.58.0-2ubuntu3.13_amd64.debLinux
SUSE-SU-2021:1396-1(SUSE Linux Enterprise Server 12-SP5 ) curl-7.60.0-11.15.1.x86_64.rpmLinux
SUSE-SU-2021:1396-1(SUSE Linux Enterprise Server 12-SP5 ) curl-debuginfo-7.60.0-11.15.1.x86_64.rpmLinux
SUSE-SU-2021:1396-1(SUSE Linux Enterprise Server 12-SP5 ) curl-debugsource-7.60.0-11.15.1.x86_64.rpmLinux
SUSE-SU-2021:1396-1(SUSE Linux Enterprise Server 12-SP5 ) libcurl4-7.60.0-11.15.1.x86_64.rpmLinux
SUSE-SU-2021:1396-1(SUSE Linux Enterprise Server 12-SP5 ) libcurl4-32bit-7.60.0-11.15.1.x86_64.rpmLinux
SUSE-SU-2021:1396-1(SUSE Linux Enterprise Server 12-SP5 ) libcurl4-debuginfo-7.60.0-11.15.1.x86_64.rpmLinux
SUSE-SU-2021:1396-1(SUSE Linux Enterprise Server 12-SP5 ) libcurl4-debuginfo-32bit-7.60.0-11.15.1.x86_64.rpmLinux
(RHSA-2021:4511) curl security and bug fix update curl-debugsource-7.61.1-22.el8.i686.rpmLinux
(RHSA-2021:4511) curl security and bug fix update curl-debugsource-7.61.1-22.el8.x86_64.rpmLinux
(RHSA-2021:4511) curl security and bug fix update libcurl-minimal-7.61.1-22.el8.i686.rpmLinux
(RHSA-2021:4511) curl security and bug fix update libcurl-minimal-7.61.1-22.el8.x86_64.rpmLinux
Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-22876)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234