CVE Vulnerabilities

CVE-2024-11053

Published: Dec 11, 2024 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

When asked to both use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances.

This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

Affected Software

NameVendorStart VersionEnd Version
CurlHaxx7.76.0 (including)8.11.1 (excluding)
Red Hat Enterprise Linux 8RedHatmysql:8.0-8100020250212154709.489197e6*
Red Hat Enterprise Linux 9RedHatmysql-0:8.0.41-2.el9_5*
CurlUbuntudevel*
CurlUbuntuesm-infra/focal*
CurlUbuntufocal*
CurlUbuntujammy*
CurlUbuntunoble*
CurlUbuntuoracular*
CurlUbuntuplucky*
CurlUbuntuquesting*
CurlUbuntutrusty/esm*

References