Back

MEDIUM

netrc and redirect credential leak

Published Dec 11, 2024

Description

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances.

This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

Affected products

Remediation

Red Hat statement

This issue only affects curl when a `.netrc` file is used and a redirect is performed. Additionally, the `.netrc` must match the target hostname but the followed-to host does not have a password or both login and password configured. Example of a vulnerable .netrc configuration: ~~~ machine a.com login alice password alicespassword default login bob ~~~

Red Hat mitigation

Avoid using the .netrc file together with redirects.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner curl
Published Dec 11, 2024
Updated Nov 3, 2025
Reserved Nov 9, 2024
CISA Vulnrichment
Updated Dec 15, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 11, 2024