libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP reque
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
즉시(3일 이내) 패치 — 최우선 대응
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H상세 설명
libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the Location: response header value. Sending the same set of headers to subsequent hosts is in particular a problem for applications that pass on custom Authorization: headers, as this header often contains privacy sensitive information or data that could allow others to impersonate the libcurl-using client's request.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- haxx curl7.1 - 7.57.0other
- debian debian_linuxlinux
- debian debian_linuxlinux
- debian debian_linuxlinux
- canonical ubuntu_linuxlinux
- canonical ubuntu_linuxlinux
- canonical ubuntu_linuxlinux
- canonical ubuntu_linuxlinux
- redhat enterprise_linux_desktoplinux
- redhat enterprise_linux_serverlinux
- redhat enterprise_linux_server_auslinux
- redhat enterprise_linux_server_euslinux
- redhat enterprise_linux_server_euslinux
- redhat enterprise_linux_workstationlinux
- fujitsu m10-1_firmware< xcp2361other
- fujitsu m10-1other
- fujitsu m10-4_firmware< xcp2361other
- fujitsu m10-4other
- fujitsu m10-4s_firmware< xcp2361other
- fujitsu m10-4sother
- fujitsu m12-1_firmware< xcp2361other
- fujitsu m12-1other
- fujitsu m12-2_firmware< xcp2361other
- fujitsu m12-2other
- fujitsu m12-2s_firmware< xcp2361other
- fujitsu m12-2sother
- fujitsu m10-1_firmware< xcp3070other
- fujitsu m10-1other
- fujitsu m10-4_firmware< xcp3070other
- fujitsu m10-4other
- fujitsu m10-4s_firmware< xcp3070other
- fujitsu m10-4sother
- fujitsu m12-1_firmware< xcp3070other
- fujitsu m12-1other
- fujitsu m12-2_firmware< xcp3070other
- fujitsu m12-2other
- fujitsu m12-2s_firmware< xcp3070other
- fujitsu m12-2sother
영향받는 구성 (CPE) 26
- haxx curl≥ 7.1 ≤ 7.57.0cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
- debian debian_linux 7.0cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
- debian debian_linux 8.0cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
- debian debian_linux 9.0cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
- canonical ubuntu_linux 12.04cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
- canonical ubuntu_linux 14.04cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- canonical ubuntu_linux 16.04cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- canonical ubuntu_linux 17.10cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
- redhat enterprise_linux_desktop 7.0cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
- redhat enterprise_linux_server 7.0cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
- redhat enterprise_linux_server_aus 7.4cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
- redhat enterprise_linux_server_eus 7.4cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*
- redhat enterprise_linux_server_eus 7.5cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
- redhat enterprise_linux_workstation 7.0cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
- fujitsu m10-1_firmware< xcp2361cpe:2.3:o:fujitsu:m10-1_firmware:*:*:*:*:*:*:*:*
- fujitsu m10-1cpe:2.3:h:fujitsu:m10-1:-:*:*:*:*:*:*:*
- fujitsu m10-4_firmware< xcp2361cpe:2.3:o:fujitsu:m10-4_firmware:*:*:*:*:*:*:*:*
- fujitsu m10-4cpe:2.3:h:fujitsu:m10-4:-:*:*:*:*:*:*:*
- fujitsu m10-4s_firmware< xcp2361cpe:2.3:o:fujitsu:m10-4s_firmware:*:*:*:*:*:*:*:*
- fujitsu m10-4scpe:2.3:h:fujitsu:m10-4s:-:*:*:*:*:*:*:*
- fujitsu m12-1_firmware< xcp2361cpe:2.3:o:fujitsu:m12-1_firmware:*:*:*:*:*:*:*:*
- fujitsu m12-1cpe:2.3:h:fujitsu:m12-1:-:*:*:*:*:*:*:*
- fujitsu m12-2_firmware< xcp2361cpe:2.3:o:fujitsu:m12-2_firmware:*:*:*:*:*:*:*:*
- fujitsu m12-2cpe:2.3:h:fujitsu:m12-2:-:*:*:*:*:*:*:*
- fujitsu m12-2s_firmware< xcp2361cpe:2.3:o:fujitsu:m12-2s_firmware:*:*:*:*:*:*:*:*
- fujitsu m12-2scpe:2.3:h:fujitsu:m12-2s:-:*:*:*:*:*:*:*
참고 자료 14
- http://www.openwall.com/lists/oss-security/2022/04/27/4Mailing ListThird Party Advisory
- http://www.securitytracker.com/id/1040274Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3157Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3558Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1543Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0544Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0594Third Party Advisory
- https://curl.haxx.se/docs/adv_2018-b3bf.htmlPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/01/msg00038.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/3554-1/Third Party Advisory
- https://usn.ubuntu.com/3554-2/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4098Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlPatchThird Party Advisory
링크 내용 불러오는 중…