DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-11053

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-11053

CGA ID

CGA-p536-wf68-h2rf

Description

When asked to both use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances.

This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images