CVE-2021-38165

Related Vulnerabilities: CVE-2021-38165  

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

Description

The MITRE CVE dictionary describes this issue as:

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

Additional Information

  • Bugzilla 1994998: CVE-2021-38165 lynx: remote attackers may discover cleartext credentials
  • CWE-522: Insufficiently Protected Credentials
  • FAQ: Frequently asked questions about CVE-2021-38165