SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances.

LOW 3.4EPSS 1.38%

Does this matter?

Lower severity and a low EPSS score (1.38%). Track it; it rarely justifies an emergency change on its own.

Description

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS 3.1
3.4 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
EPSS
1.38% probability · 71th percentile
CISA KEV
Not listed
Affected
haxx/curl · netapp/ontap · netapp/ontap select deploy administration utility · netapp/h610c firmware · netapp/h610s firmware · netapp/h615c firmware · netapp/h700s firmware · netapp/bootstrap os · netapp/h300s firmware · netapp/h410s firmware · netapp/h500s firmware
Source
2499f714-1537-4658-8207-48ae4bb9eae9

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.