SA-2024-011 - libcurl HTTP authentication leak (CVE-2018-1000007)
It was found that curl and libcurl might send their Authentication header to a third party HTTP server upon receiving an HTTP REDIRECT reply.
Equipo CECOM
5 min
SA-2024-011 - libcurl HTTP authentication leak (CVE-2018-1000007)
Resumen de la Vulnerabilidad
It was found that curl and libcurl might send their Authentication header to a third party HTTP server upon receiving an HTTP REDIRECT reply. This could leak authentication token to external entities.
Información de la Vulnerabilidad
- CVE ID: CVE-2018-1000007
- Security Advisory: SA-2024-011
- Fecha de Publicación: 29/7/2025
- Fuente: Extreme Networks Security Advisory
Para más detalles técnicos, consulte el aviso oficial de Extreme Networks.