CVE-2025-0167

Analyzed
Published: 05 Feb 2025, 09:15
Last modified:07 Mar 2025, 00:10

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
3.4 LOW
v3.1 (cve.org)
EPSS Score
0.66% LOW
1% probability +0.49%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

05 Feb 2025, 09:15
Published
Vulnerability first disclosed
07 Mar 2025, 00:10
Last Modified
Vulnerability information updated

Description

When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.

CVSS Metrics

  • v3.1LOWScore: 3.4CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

EPSS Trends

Current EPSS score: 0.66% Percentile: 47%

Affected Systems

  • curlcurl

    8.11.1 | 8.11.0 | 8.10.1 | 8.10.0 | 8.9.1 | 8.9.0 | 8.8.0 | 8.7.1 | 8.7.0 | 8.6.0 | 8.5.0 | 8.4.0 | 8.3.0 | 8.2.1 | 8.2.0 | 8.1.2 | 8.1.1 | 8.1.0 | 8.0.1 | 8.0.0 | 7.88.1 | 7.88.0 | 7.87.0 | 7.86.0 | 7.85.0 | 7.84.0 | 7.83.1 | 7.83.0 | 7.82.0 | 7.81.0 | 7.80.0 | 7.79.1 | 7.79.0 | 7.78.0 | 7.77.0 | 7.76.1 | 7.76.0

  • haxxcurl

    ≥ 7.76.0, < 8.12.0

  • netappbootstrap_os

    na

  • netappelement_software

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500s_firmware

    na

  • netapph610c_firmware

    na

  • netapph610s_firmware

    na

  • netapph615c_firmware

    na

  • netapph700s_firmware

    na

  • netappontap

    9

  • netappontap_select_deploy_administration_utility

    na

  • netappontap_tools

    9

  • netappsolidfire_\&_hci_management_node

    na

  • netappsolidfire_\&_hci_storage_node

    na

References (4)