netrc and default credential leak
Published Feb 5, 2025
3.4
LOWCVSS 3.1
EPSS 0.69%
Description
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.
Affected products
-
Affected
- 7.76.0
- 7.76.1
- 7.77.0
- 7.78.0
- 7.79.0
- 7.79.1
- 7.80.0
- 7.81.0
- 7.82.0
- 7.83.0
- 7.83.1
- 7.84.0
- 7.85.0
- 7.86.0
- 7.87.0
- 7.88.0
- 7.88.1
- 8.0.0
- 8.0.1
- 8.1.0
- 8.1.1
- 8.1.2
- 8.10.0
- 8.10.1
- 8.11.0
- 8.11.1
- 8.2.0
- 8.2.1
- 8.3.0
- 8.4.0
- 8.5.0
- 8.6.0
- 8.7.0
- 8.7.1
- 8.8.0
- 8.9.0
- 8.9.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
Configuration 2
- n/a
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Running on/with
- n/a
Configuration 11
- n/a
- 9
- n/a
- 9
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (5)
- https://curl.se/docs/CVE-2025-0167.html exploitVendor Advisory
- https://curl.se/docs/CVE-2025-0167.json Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-1518 Advisory
- https://hackerone.com/reports/2917232 ExploitIssue TrackingThird Party Advisory
- https://security.netapp.com/advisory/ntap-20250306-0008/ Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://curl.se/docs/CVE-2025-0167.html | exploitVendor Advisory | |
| https://curl.se/docs/CVE-2025-0167.json | Vendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-1518 | Advisory | |
| https://hackerone.com/reports/2917232 | ExploitIssue TrackingThird Party Advisory | |
| https://security.netapp.com/advisory/ntap-20250306-0008/ | Third Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data