Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
CURL-CVE-2018-1000007
No affected components available
curl might leak authentication data to third parties.
When asked to send custom headers in its HTTP requests, curl sends that set of
headers first to the host in the initial URL but also, if asked to follow
redirects and a 30X HTTP response code is returned, to the host mentioned in
URL in the Location: response header value.
Sending the same set of headers to subsequent hosts is in particular a problem
for applications that pass on custom Authorization: headers, as this header
often contains privacy sensitive information or data that could allow others
to impersonate the curl-using client's request.
Measures severity based on intrinsic characteristics of the vulnerability, independent of environment.
No exploitation activity has been observed at this time. Continue routine monitoring.
The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard