Kestrel
대시보드로 돌아가기
CVE-2018-1000007CRITICAL· 9.8MITRENVD대응게시일: 2018. 01. 24.수정일: 2024. 11. 21.CNA: cve@mitre.orgModified

libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP reque

위협 신호 · CVSS · EPSS · KEV

시급 검토· 이론 심각도 Critical
CVSS
9.8critical

이론적 심각도 점수

EPSS
8.0%상위 5.4%

30일 내 악용 확률 예측

KEV
미등재

실측 악용 기록 없음

권장 대응 기한3일 이내CISA SSVC 기준

즉시(3일 이내) 패치 — 최우선 대응

자동화 가능완전 장악외부 노출· KEV 미등재 · 자동화 가능 · 완전 장악 · 외부 노출

CVSS 벡터 · 메트릭

악용 경로
공격 벡터네트워크
공격 복잡도낮음
필요 권한불필요
사용자 상호작용불필요
범위불변
영향
기밀성 영향높음
무결성 영향높음
가용성 영향높음
버전별 점수
CVSS 3.19.8CRITICAL· 악용성 3.9· 영향도 5.9
CVSS 2.05.0MEDIUM· 악용성 10· 영향도 2.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

상세 설명

libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the Location: response header value. Sending the same set of headers to subsequent hosts is in particular a problem for applications that pass on custom Authorization: headers, as this header often contains privacy sensitive information or data that could allow others to impersonate the libcurl-using client's request.

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.

영향받는 제품·버전

  • haxx curl7.1 - 7.57.0
    other
  • debian debian_linux
    linux
  • debian debian_linux
    linux
  • debian debian_linux
    linux
  • canonical ubuntu_linux
    linux
  • canonical ubuntu_linux
    linux
  • canonical ubuntu_linux
    linux
  • canonical ubuntu_linux
    linux
  • redhat enterprise_linux_desktop
    linux
  • redhat enterprise_linux_server
    linux
  • redhat enterprise_linux_server_aus
    linux
  • redhat enterprise_linux_server_eus
    linux
  • redhat enterprise_linux_server_eus
    linux
  • redhat enterprise_linux_workstation
    linux
  • fujitsu m10-1_firmware< xcp2361
    other
  • fujitsu m10-1
    other
  • fujitsu m10-4_firmware< xcp2361
    other
  • fujitsu m10-4
    other
  • fujitsu m10-4s_firmware< xcp2361
    other
  • fujitsu m10-4s
    other
  • fujitsu m12-1_firmware< xcp2361
    other
  • fujitsu m12-1
    other
  • fujitsu m12-2_firmware< xcp2361
    other
  • fujitsu m12-2
    other
  • fujitsu m12-2s_firmware< xcp2361
    other
  • fujitsu m12-2s
    other
  • fujitsu m10-1_firmware< xcp3070
    other
  • fujitsu m10-1
    other
  • fujitsu m10-4_firmware< xcp3070
    other
  • fujitsu m10-4
    other
  • fujitsu m10-4s_firmware< xcp3070
    other
  • fujitsu m10-4s
    other
  • fujitsu m12-1_firmware< xcp3070
    other
  • fujitsu m12-1
    other
  • fujitsu m12-2_firmware< xcp3070
    other
  • fujitsu m12-2
    other
  • fujitsu m12-2s_firmware< xcp3070
    other
  • fujitsu m12-2s
    other

영향받는 구성 (CPE) 26

  • haxx curl≥ 7.1 ≤ 7.57.0cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
  • debian debian_linux 7.0cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • debian debian_linux 8.0cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • debian debian_linux 9.0cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • canonical ubuntu_linux 12.04cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
  • canonical ubuntu_linux 14.04cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
  • canonical ubuntu_linux 16.04cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
  • canonical ubuntu_linux 17.10cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
  • redhat enterprise_linux_desktop 7.0cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
  • redhat enterprise_linux_server 7.0cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
  • redhat enterprise_linux_server_aus 7.4cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
  • redhat enterprise_linux_server_eus 7.4cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*
  • redhat enterprise_linux_server_eus 7.5cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
  • redhat enterprise_linux_workstation 7.0cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
  • fujitsu m10-1_firmware< xcp2361cpe:2.3:o:fujitsu:m10-1_firmware:*:*:*:*:*:*:*:*
  • fujitsu m10-1cpe:2.3:h:fujitsu:m10-1:-:*:*:*:*:*:*:*
  • fujitsu m10-4_firmware< xcp2361cpe:2.3:o:fujitsu:m10-4_firmware:*:*:*:*:*:*:*:*
  • fujitsu m10-4cpe:2.3:h:fujitsu:m10-4:-:*:*:*:*:*:*:*
  • fujitsu m10-4s_firmware< xcp2361cpe:2.3:o:fujitsu:m10-4s_firmware:*:*:*:*:*:*:*:*
  • fujitsu m10-4scpe:2.3:h:fujitsu:m10-4s:-:*:*:*:*:*:*:*
  • fujitsu m12-1_firmware< xcp2361cpe:2.3:o:fujitsu:m12-1_firmware:*:*:*:*:*:*:*:*
  • fujitsu m12-1cpe:2.3:h:fujitsu:m12-1:-:*:*:*:*:*:*:*
  • fujitsu m12-2_firmware< xcp2361cpe:2.3:o:fujitsu:m12-2_firmware:*:*:*:*:*:*:*:*
  • fujitsu m12-2cpe:2.3:h:fujitsu:m12-2:-:*:*:*:*:*:*:*
  • fujitsu m12-2s_firmware< xcp2361cpe:2.3:o:fujitsu:m12-2s_firmware:*:*:*:*:*:*:*:*
  • fujitsu m12-2scpe:2.3:h:fujitsu:m12-2s:-:*:*:*:*:*:*:*