CVE-2021-22876
Summary
| CVE | CVE-2021-22876 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-01 18:15:00 UTC |
| Updated | 2024-03-27 15:47:00 UTC |
| Description | curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 32 Update: curl-7.69.1-8.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: curl-7.71.1-9.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: curl-7.76.0-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| cURL: Multiple vulnerabilities (GLSA 202105-36) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Oracle Critical Patch Update Advisory - July 2021 |
N/A |
www.oracle.com |
|
| [SECURITY] [DLA 2664-1] curl security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 32 Update: curl-7.69.1-8.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| HackerOne |
MISC |
hackerone.com |
|
| cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| [SECURITY] Fedora 34 Update: curl-7.76.0-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: curl-7.71.1-9.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| curl - Automatic referer leaks credentials - CVE-2021-22876 |
MISC |
curl.se |
|
| April 2021 cURL/libcURL Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159520 Oracle Enterprise Linux Security Update for curl (ELSA-2021-4511)
- 174942 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2021:1006-1)
- 174951 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2021:14707-1)
- 174956 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2021:1396-1)
- 178522 Debian Security Update for curl (DSA 4881-1)
- 178600 Debian Security Update for curl (DLA 2664-1)
- 180068 Debian Security Update for curl (CVE-2021-22876)
- 198316 Ubuntu Security Notification for Curl Vulnerabilities (USN-4898-1)
- 239451 Red Hat Update for Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP8 (RHSA-2021:2472)
- 239832 Red Hat Update for curl (RHSA-2021:4511)
- 240217 Red Hat Update for rh-dotnet31-curl (RHSA-2022:1354)
- 281384 Fedora Security Update for curl (FEDORA-2021-cab5c9befb)
- 281385 Fedora Security Update for curl (FEDORA-2021-065371f385)
- 281386 Fedora Security Update for curl (FEDORA-2021-26a293c72b)
- 296059 Oracle Solaris 11.4 Support Repository Update (SRU) 36.0.1.101.2 Missing (CPUJUL2021)
- 352402 Amazon Linux Security Advisory for curl: ALAS2-2021-1653
- 352482 Amazon Linux Security Advisory for curl: ALAS-2021-1509
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 500134 Alpine Linux Security Update for curl
- 503785 Alpine Linux Security Update for curl
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 670440 EulerOS Security Update for curl (EulerOS-SA-2021-2060)
- 670451 EulerOS Security Update for curl (EulerOS-SA-2021-2049)
- 670699 EulerOS Security Update for curl (EulerOS-SA-2021-2457)
- 670903 EulerOS Security Update for curl (EulerOS-SA-2021-2060)
- 690175 Free Berkeley Software Distribution (FreeBSD) Security Update for curl (b1194286-958e-11eb-9c34-080027f515ea)
- 710078 Gentoo Linux cURL Multiple vulnerabilities (GLSA 202105-36)
- 730155 McAfee Web Gateway Multiple Vulnerabilities(WP-3580, WP-3656, WP-3815, WP-3878, WP-3882, WP-3934,WP-3935, WP-3936, WP-3999)
- 750055 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2021:1786-1)
- 750081 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2021:1809-1)
- 750283 OpenSUSE Security Update for curl (openSUSE-SU-2021:0510-1)
- 900252 CBL-Mariner Linux Security Update for curl 7.76.0
- 940095 AlmaLinux Security Update for curl (ALSA-2021:4511)