LOW · 3.4

CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This fla...

Vulnerability Description

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS Score

3.4

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HaxxCurl>= 7.76.0, < 8.11.1
NetappOntap9
NetappOntap Select Deploy Administration Utility-
NetappH610C Firmware-
NetappH610C-
NetappH610S Firmware-
NetappH610S-
NetappH615C Firmware-
NetappH615C-
NetappH700S Firmware-
NetappH700S-
NetappBootstrap Os-
NetappHci Compute Node-
NetappH300S Firmware-
NetappH300S-
NetappH410S Firmware-
NetappH410S-
NetappH500S Firmware-
NetappH500S-

References

FAQ

What is CVE-2024-11053?

CVE-2024-11053 is a vulnerability with a CVSS score of 3.4 (LOW). When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This fla...

How severe is CVE-2024-11053?

CVE-2024-11053 has been rated LOW with a CVSS base score of 3.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-11053?

Check the references section above for vendor advisories and patch information. Affected products include: Haxx Curl, Netapp Ontap, Netapp Ontap Select Deploy Administration Utility, Netapp H610C Firmware, Netapp H610C.