CVE-2025-0167
Advisory lineage Upstream: 0 Downstream: 10
Analyzed
Published: 05 Feb 2025, 09:15
Last modified:07 Mar 2025, 00:10
Vulnerability Summary
Overall Risk (default)
low
24/100 CVSS Score
3.4 LOW
v3.1 (cve.org)
EPSS Score
0.66% LOW
1% probability +0.49%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
05 Feb 2025, 09:15
Published
Vulnerability first disclosed
07 Mar 2025, 00:10
Last Modified
Vulnerability information updated
Description
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.
CVSS Metrics
- v3.1•LOW•Score: 3.4CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
EPSS Trends
Current EPSS score: 0.66%• Percentile: 47%
Affected Systems
- curl•curl
8.11.1 | 8.11.0 | 8.10.1 | 8.10.0 | 8.9.1 | 8.9.0 | 8.8.0 | 8.7.1 | 8.7.0 | 8.6.0 | 8.5.0 | 8.4.0 | 8.3.0 | 8.2.1 | 8.2.0 | 8.1.2 | 8.1.1 | 8.1.0 | 8.0.1 | 8.0.0 | 7.88.1 | 7.88.0 | 7.87.0 | 7.86.0 | 7.85.0 | 7.84.0 | 7.83.1 | 7.83.0 | 7.82.0 | 7.81.0 | 7.80.0 | 7.79.1 | 7.79.0 | 7.78.0 | 7.77.0 | 7.76.1 | 7.76.0
- haxx•curl
≥ 7.76.0, < 8.12.0
- netapp•bootstrap_os
na
- netapp•element_software
na
- netapp•h300s_firmware
na
- netapp•h410c_firmware
na
- netapp•h410s_firmware
na
- netapp•h500s_firmware
na
- netapp•h610c_firmware
na
- netapp•h610s_firmware
na
- netapp•h615c_firmware
na
- netapp•h700s_firmware
na
- netapp•ontap
9
- netapp•ontap_select_deploy_administration_utility
na
- netapp•ontap_tools
9
- netapp•solidfire_\&_hci_management_node
na
- netapp•solidfire_\&_hci_storage_node
na