Related Vulnerabilities: CVE-2022-27774  

curl leaks credentials to other servers when it follows redirects from auth protected HTTP(S) URLs to other protocols and port numbers. It could also leak the TLS SRP credentials this way.

Severity Medium

Remote No

Type Information disclosure

Description

curl leaks credentials to other servers when it follows redirects from auth protected HTTP(S) URLs to other protocols and port numbers. It could also leak the TLS SRP credentials this way.

AVG-2685 curl 7.82.0-3 Medium Vulnerable

https://curl.se/docs/CVE-2022-27774.html

We are not aware of any exploit of this flaw.