icon

We found results for “

CVE-2025-0167

Good to know:

icon

Date: February 5, 2025

In curl before 8.12.0, when asked to use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a default entry that omits both login and password. A rare circumstance.

Severity Score

Severity Score

Top Fix

icon

Upgrade Version

Upgrade to version https://github.com/curl/curl.git - curl-8_12_0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us