The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Information
Published : 2015-05-01 08:59
Updated : 2018-10-16 18:29
NVD link : CVE-2015-3153
Mitre link : CVE-2015-3153
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
debian
- debian_linux
haxx
- curl
- libcurl
canonical
- ubuntu_linux
apple
- mac_os_x
oracle
- enterprise_manager_ops_center