DEBIAN-CVE-2024-11053

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 11 Dec 2024, 08:15
Last modified:15 Jun 2026, 19:04

Vulnerability Summary

Overall Risk (default)
low
14/100
CVSS Score
3.4 LOW
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Dec 2024, 08:15
Published
Vulnerability first disclosed
15 Jun 2026, 19:04
Last Modified
Vulnerability information updated

Description

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

CVSS Metrics

  • v3.1LOWScore: 3.4CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

Affected Systems

  • debiancurl

    < 7.88.1-10+deb12u10 | < 8.11.1-1 | < 8.11.1-1

References (1)