Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.10.6, < 8.21.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
>= 7.10.6, <= 7.10.6CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.10.7, <= 7.10.7CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.10.8, <= 7.10.8CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.11.0, <= 7.11.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.