CVE-2024-11053
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances.
Does this matter?
Lower severity and a low EPSS score (1.38%). Track it; it rarely justifies an emergency change on its own.
Description
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.
- CVSS 3.1
- 3.4 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
- EPSS
- 1.38% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- haxx/curl · netapp/ontap · netapp/ontap select deploy administration utility · netapp/h610c firmware · netapp/h610s firmware · netapp/h615c firmware · netapp/h700s firmware · netapp/bootstrap os · netapp/h300s firmware · netapp/h410s firmware · netapp/h500s firmware
- Source
- 2499f714-1537-4658-8207-48ae4bb9eae9
References
- https://curl.se/docs/CVE-2024-11053.htmlVendor Advisory
- https://curl.se/docs/CVE-2024-11053.jsonVendor Advisory
- https://hackerone.com/reports/2829063Exploit, Issue Tracking, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2024/12/11/1Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20250124-0012/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20250131-0003/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20250131-0004/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.