Vulnerability Details CVE-2021-22876
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.3%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2021-22876
-
cpe:2.3:a:haxx:libcurl:7.1.1
-
cpe:2.3:a:haxx:libcurl:7.10
-
cpe:2.3:a:haxx:libcurl:7.10.1
-
cpe:2.3:a:haxx:libcurl:7.10.2
-
cpe:2.3:a:haxx:libcurl:7.10.3
-
cpe:2.3:a:haxx:libcurl:7.10.4
-
cpe:2.3:a:haxx:libcurl:7.10.5
-
cpe:2.3:a:haxx:libcurl:7.10.6
-
cpe:2.3:a:haxx:libcurl:7.10.7
-
cpe:2.3:a:haxx:libcurl:7.10.8
-
cpe:2.3:a:haxx:libcurl:7.11.0
-
cpe:2.3:a:haxx:libcurl:7.11.1
-
cpe:2.3:a:haxx:libcurl:7.11.2
-
cpe:2.3:a:haxx:libcurl:7.12.0
-
cpe:2.3:a:haxx:libcurl:7.12.1
-
cpe:2.3:a:haxx:libcurl:7.12.2
-
cpe:2.3:a:haxx:libcurl:7.12.3
-
cpe:2.3:a:haxx:libcurl:7.13.0
-
cpe:2.3:a:haxx:libcurl:7.13.1
-
cpe:2.3:a:haxx:libcurl:7.13.2
-
cpe:2.3:a:haxx:libcurl:7.14.0
-
cpe:2.3:a:haxx:libcurl:7.14.1
-
cpe:2.3:a:haxx:libcurl:7.15.0
-
cpe:2.3:a:haxx:libcurl:7.15.1
-
cpe:2.3:a:haxx:libcurl:7.15.2
-
cpe:2.3:a:haxx:libcurl:7.15.3
-
cpe:2.3:a:haxx:libcurl:7.15.4
-
cpe:2.3:a:haxx:libcurl:7.15.5
-
cpe:2.3:a:haxx:libcurl:7.16.0
-
cpe:2.3:a:haxx:libcurl:7.16.1
-
cpe:2.3:a:haxx:libcurl:7.16.2
-
cpe:2.3:a:haxx:libcurl:7.16.3
-
cpe:2.3:a:haxx:libcurl:7.16.4
-
cpe:2.3:a:haxx:libcurl:7.17.0
-
cpe:2.3:a:haxx:libcurl:7.17.1
-
cpe:2.3:a:haxx:libcurl:7.18.0
-
cpe:2.3:a:haxx:libcurl:7.18.1
-
cpe:2.3:a:haxx:libcurl:7.18.2
-
cpe:2.3:a:haxx:libcurl:7.19.0
-
cpe:2.3:a:haxx:libcurl:7.19.1
-
cpe:2.3:a:haxx:libcurl:7.19.2
-
cpe:2.3:a:haxx:libcurl:7.19.3
-
cpe:2.3:a:haxx:libcurl:7.19.4
-
cpe:2.3:a:haxx:libcurl:7.19.5
-
cpe:2.3:a:haxx:libcurl:7.19.6
-
cpe:2.3:a:haxx:libcurl:7.19.7
-
cpe:2.3:a:haxx:libcurl:7.2
-
cpe:2.3:a:haxx:libcurl:7.2.1
-
cpe:2.3:a:haxx:libcurl:7.20.0
-
cpe:2.3:a:haxx:libcurl:7.20.1
-
cpe:2.3:a:haxx:libcurl:7.21.0
-
cpe:2.3:a:haxx:libcurl:7.21.1
-
cpe:2.3:a:haxx:libcurl:7.21.2
-
cpe:2.3:a:haxx:libcurl:7.21.3
-
cpe:2.3:a:haxx:libcurl:7.21.4
-
cpe:2.3:a:haxx:libcurl:7.21.5
-
cpe:2.3:a:haxx:libcurl:7.21.6
-
cpe:2.3:a:haxx:libcurl:7.21.7
-
cpe:2.3:a:haxx:libcurl:7.22.0
-
cpe:2.3:a:haxx:libcurl:7.23.0
-
cpe:2.3:a:haxx:libcurl:7.23.1
-
cpe:2.3:a:haxx:libcurl:7.24.0
-
cpe:2.3:a:haxx:libcurl:7.25.0
-
cpe:2.3:a:haxx:libcurl:7.26.0
-
cpe:2.3:a:haxx:libcurl:7.27.0
-
cpe:2.3:a:haxx:libcurl:7.28.0
-
cpe:2.3:a:haxx:libcurl:7.28.1
-
cpe:2.3:a:haxx:libcurl:7.29.0
-
cpe:2.3:a:haxx:libcurl:7.3
-
cpe:2.3:a:haxx:libcurl:7.30.0
-
cpe:2.3:a:haxx:libcurl:7.31.0
-
cpe:2.3:a:haxx:libcurl:7.32.0
-
cpe:2.3:a:haxx:libcurl:7.33.0
-
cpe:2.3:a:haxx:libcurl:7.34.0
-
cpe:2.3:a:haxx:libcurl:7.35.0
-
cpe:2.3:a:haxx:libcurl:7.36.0
-
cpe:2.3:a:haxx:libcurl:7.37.0
-
cpe:2.3:a:haxx:libcurl:7.37.1
-
cpe:2.3:a:haxx:libcurl:7.38.0
-
cpe:2.3:a:haxx:libcurl:7.39
-
cpe:2.3:a:haxx:libcurl:7.39.0
-
cpe:2.3:a:haxx:libcurl:7.4
-
cpe:2.3:a:haxx:libcurl:7.4.1
-
cpe:2.3:a:haxx:libcurl:7.4.2
-
cpe:2.3:a:haxx:libcurl:7.40.0
-
cpe:2.3:a:haxx:libcurl:7.41.0
-
cpe:2.3:a:haxx:libcurl:7.42
-
cpe:2.3:a:haxx:libcurl:7.42.0
-
cpe:2.3:a:haxx:libcurl:7.42.1
-
cpe:2.3:a:haxx:libcurl:7.43.0
-
cpe:2.3:a:haxx:libcurl:7.44.0
-
cpe:2.3:a:haxx:libcurl:7.45.0
-
cpe:2.3:a:haxx:libcurl:7.46.0
-
cpe:2.3:a:haxx:libcurl:7.47.0
-
cpe:2.3:a:haxx:libcurl:7.47.1
-
cpe:2.3:a:haxx:libcurl:7.48.0
-
cpe:2.3:a:haxx:libcurl:7.49.0
-
cpe:2.3:a:haxx:libcurl:7.49.1
-
cpe:2.3:a:haxx:libcurl:7.5
-
cpe:2.3:a:haxx:libcurl:7.5.1
-
cpe:2.3:a:haxx:libcurl:7.5.2
-
cpe:2.3:a:haxx:libcurl:7.50.0
-
cpe:2.3:a:haxx:libcurl:7.50.1
-
cpe:2.3:a:haxx:libcurl:7.50.2
-
cpe:2.3:a:haxx:libcurl:7.50.3
-
cpe:2.3:a:haxx:libcurl:7.51.0
-
cpe:2.3:a:haxx:libcurl:7.52.0
-
cpe:2.3:a:haxx:libcurl:7.52.1
-
cpe:2.3:a:haxx:libcurl:7.53.0
-
cpe:2.3:a:haxx:libcurl:7.53.1
-
cpe:2.3:a:haxx:libcurl:7.54.0
-
cpe:2.3:a:haxx:libcurl:7.54.1
-
cpe:2.3:a:haxx:libcurl:7.55.0
-
cpe:2.3:a:haxx:libcurl:7.55.1
-
cpe:2.3:a:haxx:libcurl:7.56.0
-
cpe:2.3:a:haxx:libcurl:7.56.1
-
cpe:2.3:a:haxx:libcurl:7.57.0
-
cpe:2.3:a:haxx:libcurl:7.58.0
-
cpe:2.3:a:haxx:libcurl:7.59.0
-
cpe:2.3:a:haxx:libcurl:7.6
-
cpe:2.3:a:haxx:libcurl:7.6.1
-
cpe:2.3:a:haxx:libcurl:7.60.0
-
cpe:2.3:a:haxx:libcurl:7.61.0
-
cpe:2.3:a:haxx:libcurl:7.61.1
-
cpe:2.3:a:haxx:libcurl:7.62.0
-
cpe:2.3:a:haxx:libcurl:7.63.0
-
cpe:2.3:a:haxx:libcurl:7.64.0
-
cpe:2.3:a:haxx:libcurl:7.64.1
-
cpe:2.3:a:haxx:libcurl:7.65.0
-
cpe:2.3:a:haxx:libcurl:7.65.1
-
cpe:2.3:a:haxx:libcurl:7.65.2
-
cpe:2.3:a:haxx:libcurl:7.65.3
-
cpe:2.3:a:haxx:libcurl:7.66.0
-
cpe:2.3:a:haxx:libcurl:7.67.0
-
cpe:2.3:a:haxx:libcurl:7.68.0
-
cpe:2.3:a:haxx:libcurl:7.69.0
-
cpe:2.3:a:haxx:libcurl:7.69.1
-
cpe:2.3:a:haxx:libcurl:7.7
-
cpe:2.3:a:haxx:libcurl:7.7.1
-
cpe:2.3:a:haxx:libcurl:7.7.2
-
cpe:2.3:a:haxx:libcurl:7.7.3
-
cpe:2.3:a:haxx:libcurl:7.70.0
-
cpe:2.3:a:haxx:libcurl:7.71.0
-
cpe:2.3:a:haxx:libcurl:7.71.1
-
cpe:2.3:a:haxx:libcurl:7.72.0
-
cpe:2.3:a:haxx:libcurl:7.73.0
-
cpe:2.3:a:haxx:libcurl:7.74.0
-
cpe:2.3:a:haxx:libcurl:7.75.0
-
cpe:2.3:a:haxx:libcurl:7.8
-
cpe:2.3:a:haxx:libcurl:7.8.1
-
cpe:2.3:a:haxx:libcurl:7.9
-
cpe:2.3:a:haxx:libcurl:7.9.1
-
cpe:2.3:a:haxx:libcurl:7.9.2
-
cpe:2.3:a:haxx:libcurl:7.9.3
-
cpe:2.3:a:haxx:libcurl:7.9.4
-
cpe:2.3:a:haxx:libcurl:7.9.5
-
cpe:2.3:a:haxx:libcurl:7.9.6
-
cpe:2.3:a:haxx:libcurl:7.9.7
-
cpe:2.3:a:haxx:libcurl:7.9.8
-
cpe:2.3:a:netapp:hci_management_node:-
-
cpe:2.3:a:netapp:solidfire:-
-
cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0
-
cpe:2.3:a:oracle:essbase:21.2
-
cpe:2.3:a:siemens:sinec_infrastructure_network_services:-
-
cpe:2.3:a:siemens:sinec_infrastructure_network_services:1.0.1
-
cpe:2.3:a:splunk:universal_forwarder:8.2.0
-
cpe:2.3:a:splunk:universal_forwarder:8.2.10
-
cpe:2.3:a:splunk:universal_forwarder:8.2.11
-
cpe:2.3:a:splunk:universal_forwarder:8.2.6
-
cpe:2.3:a:splunk:universal_forwarder:8.2.7
-
cpe:2.3:a:splunk:universal_forwarder:8.2.8
-
cpe:2.3:a:splunk:universal_forwarder:8.2.9
-
cpe:2.3:a:splunk:universal_forwarder:9.0.0
-
cpe:2.3:a:splunk:universal_forwarder:9.0.1
-
cpe:2.3:a:splunk:universal_forwarder:9.0.2
-
cpe:2.3:a:splunk:universal_forwarder:9.0.3
-
cpe:2.3:a:splunk:universal_forwarder:9.0.4
-
cpe:2.3:a:splunk:universal_forwarder:9.0.5
-
cpe:2.3:a:splunk:universal_forwarder:9.1.0
-
cpe:2.3:h:netapp:hci_compute_node:-
-
cpe:2.3:h:netapp:hci_storage_node:-
-
cpe:2.3:o:broadcom:fabric_operating_system:-
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:fedoraproject:fedora:32
-
cpe:2.3:o:fedoraproject:fedora:33
-
cpe:2.3:o:fedoraproject:fedora:34