When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.11.1, < 8.21.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
>= 8.11.1, <= 8.11.1CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 8.12.0, <= 8.12.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 8.12.1, <= 8.12.1CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 8.13.0, <= 8.13.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.