libcurl: partial password leak over DNS on HTTP redirect
Published Dec 14, 2020
7.5
HIGHCVSS 3.1
EPSS 3.47%
Description
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
Affected products
No data.
Configuration 2
- < 2.2
Running on/with
- n/a
Configuration 3
- 10.0
Configuration 4
- < 1.0.1.1
Configuration 5
- ≥ 8.2.0 · < 8.2.12
- ≥ 9.0.0 · < 9.0.6
- 9.1.0
No data.
JBoss Core Services Apache HTTP Server 2.4.37 SP8
jbcs-httpd24-curl
Fixed · RHSA-2021:2471
JBoss Core Services for RHEL 8
jbcs-httpd24-0:1-18.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-apr-0:1.6.3-105.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-apr-util-0:1.6.1-82.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-brotli-0:1.0.6-40.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-curl-0:7.77.0-2.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-httpd-0:2.4.37-74.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-jansson-0:2.11-55.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_cluster-native-0:1.3.16-5.Final_redhat_2.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_http2-0:1.15.7-17.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_jk-0:1.2.48-16.redhat_1.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_md-1:2.0.8-36.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_security-0:2.9.2-63.GA.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-nghttp2-0:1.39.2-37.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-openssl-1:1.1.1g-6.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-openssl-chil-0:1.0.0-5.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-openssl-pkcs11-0:0.4.10-20.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-0:1-18.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-0:1.6.3-105.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-util-0:1.6.1-82.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-curl-0:7.77.0-2.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.37-74.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-jansson-0:2.11-55.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.16-5.Final_redhat_2.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_http2-0:1.15.7-17.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_jk-0:1.2.48-16.redhat_1.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_md-1:2.0.8-36.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_security-0:2.9.2-63.GA.jbcs.el7
Fixed · RHSA-2021:2472
.NET Core 2.1 on Red Hat Enterprise Linux
rh-dotnet21-curl
Not affected
.NET Core 3.1 on Red Hat Enterprise Linux
rh-dotnet31-curl
Not affected
Red Hat Ceph Storage 2
curl
Out of support scope
Red Hat Enterprise Linux 5
curl
Not affected
Red Hat Enterprise Linux 6
curl
Not affected
Red Hat Enterprise Linux 7
curl
Not affected
Red Hat Enterprise Linux 8
curl
Not affected
Red Hat Software Collections
httpd24-curl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services Apache HTTP Server 2.4.37 SP8 | jbcs-httpd24-curl | Fixed | RHSA-2021:2471 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-0:1-18.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-apr-0:1.6.3-105.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-apr-util-0:1.6.1-82.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-brotli-0:1.0.6-40.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-curl-0:7.77.0-2.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd-0:2.4.37-74.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-jansson-0:2.11-55.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_cluster-native-0:1.3.16-5.Final_redhat_2.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_http2-0:1.15.7-17.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_jk-0:1.2.48-16.redhat_1.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_md-1:2.0.8-36.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_security-0:2.9.2-63.GA.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-nghttp2-0:1.39.2-37.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-openssl-1:1.1.1g-6.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-openssl-chil-0:1.0.0-5.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-openssl-pkcs11-0:0.4.10-20.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-0:1-18.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-0:1.6.3-105.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-util-0:1.6.1-82.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-curl-0:7.77.0-2.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.37-74.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-jansson-0:2.11-55.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.16-5.Final_redhat_2.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_http2-0:1.15.7-17.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_jk-0:1.2.48-16.redhat_1.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_md-1:2.0.8-36.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_security-0:2.9.2-63.GA.jbcs.el7 | Fixed | RHSA-2021:2472 |
| .NET Core 2.1 on Red Hat Enterprise Linux | rh-dotnet21-curl | Not affected | n/a |
| .NET Core 3.1 on Red Hat Enterprise Linux | rh-dotnet31-curl | Not affected | n/a |
| Red Hat Ceph Storage 2 | curl | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | curl | Not affected | n/a |
| Red Hat Software Collections | httpd24-curl | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2020-8169 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1847916 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-200951.pdf x_refsource_CONFIRMThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf x_refsource_CONFIRMPatchThird Party Advisory
- https://curl.haxx.se/docs/CVE-2020-8169.html
- https://curl.se/docs/CVE-2020-8169.html x_refsource_MISCVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29053 Advisory
- https://hackerone.com/reports/874778 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8169
- https://www.cve.org/CVERecord?id=CVE-2020-8169
- https://www.debian.org/security/2021/dsa-4881 vendor-advisoryx_refsource_DEBIANThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-8169 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1847916 | Issue Tracking | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-200951.pdf | x_refsource_CONFIRMThird Party Advisory | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://curl.haxx.se/docs/CVE-2020-8169.html | ||
| https://curl.se/docs/CVE-2020-8169.html | x_refsource_MISCVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29053 | Advisory | |
| https://hackerone.com/reports/874778 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-8169 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-8169 | ||
| https://www.debian.org/security/2021/dsa-4881 | vendor-advisoryx_refsource_DEBIANThird Party Advisory |
Change history (0)
No recorded changes yet.