curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.
| Software | From | Fixed in |
|---|---|---|
| haxx / libcurl | 7.1.1 | 7.75.0.x |
| fedoraproject / fedora | 32 | 32.x |
| fedoraproject / fedora | 33 | 33.x |
| fedoraproject / fedora | 34 | 34.x |
| debian / debian_linux | 9.0 | 9.0.x |
| siemens / sinec_infrastructure_network_services | - | 1.0.1.1 |
| oracle / communications_billing_and_revenue_management | 12.0.0.3.0 | 12.0.0.3.0.x |
| oracle / essbase | 21.2 | 21.2.x |
| splunk / universal_forwarder | 9.1.0 | 9.1.0.x |
| splunk / universal_forwarder | 9.0.0 | 9.0.6 |
| splunk / universal_forwarder | 8.2.0 | 8.2.12 |