Overview
About vulnerability
When asking curl to use a.netrc file to find credentials and at the same
time specifying a URL with a username(without a password), like
https://[email protected]/, curl could wrongly get and use the password for
another user set in the .netrc file for that host if such a one exists and
there is no match for the specified user.
Details
- Affected product:
- AlmaLinux 9.2 ESU , Alpine Linux 3.18 ELS , CentOS 6 ELS , CentOS 7 ELS , CentOS 8.4 ELS , CentOS 8.5 ELS , CentOS Stream 8 ELS , RHEL 7 ELS , TuxCare 9.6 ESU , Ubuntu 16.04 ELS , Ubuntu 18.04 ELS , Ubuntu 20.04 ELS
- Affected packages:
- curl @ 7.68.0 (+11 more)