← Back

CVE-2021-22876

nvd nist
Published: Apr 1, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.

Affected (16)

Show all products
1 product
Libcurl
1 product
Fedora
4 products
Hci Compute Node
Hci Management Node
Hci Storage Node
Solidfire
1 product
Fabric Operating System
1 product
Debian Linux
1 product
2 products
Essbase
1 product
Universal Forwarder
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 7.1.1 to 7.75.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33
Version 34
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.0.1.1
Configuration G
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0.0.3.0
Version 21.2
Configuration H
3 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 8.2.0 to 8.2.12
From 9.0.0 to 9.0.6
Version 9.1.0

References (20)

Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
PatchVendor Advisory
Source: support@hackerone.com
ExploitIssue TrackingPatchThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.