CVE-2022-27776

MEDIUM6.5EPSS 0.68%
Published: 6/2/2022Modified: 12/3/2025
Also known as:ALPINE-CVE-2022-27776

Description

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

References (2)