curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://hackerone.com/reports/874778 | third party advisory exploit |
https://curl.se/docs/CVE-2020-8169.html | vendor advisory |
https://www.debian.org/security/2021/dsa-4881 | third party advisory vendor advisory |
https://cert-portal.siemens.com/productcert/pdf/ssa-200951.pdf | third party advisory |
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | third party advisory patch |