PT-2021-6778 · Curl+7 · Curl+7

Published

2021-07-21

·

Updated

2026-05-18

·

CVE-2021-22923

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions curl versions prior to 7.77.0
Description The issue is related to insufficient protection of registration data, allowing a remote attacker to access confidential data. When curl is instructed to get content using the metalink feature and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from, often contrary to the user's expectations and intentions and without telling the user it happened.
Recommendations For versions prior to 7.77.0, update to version 7.77.0 or later to resolve the issue. As a temporary workaround, consider disabling the metalink feature until a patch is available. Avoid using the username and password variables in the affected API endpoint until the issue is resolved. Restrict access to the metalink XML file to minimize the risk of exploitation.

Exploit

Fix

Insufficiently Protected Credentials

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2348
ALT-PU-2021-2856
ALT-PU-2021-2908
ALT-PU-2021-3241
ALT-PU-2021-3666
ALT-PU-2022-2171
ALT-PU-2023-1912
AZL-6362
BDU:2022-02170
CESA-2021_3582
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2021-22923
MGASA-2021-0384
OESA-2022-1506
OPENSUSE-SU-2021:1088-1
OPENSUSE-SU-2021:2439-1
OPENSUSE-SU-2021_1088-1
OPENSUSE-SU-2021_2439-1
OPENSUSE-SU-2024:12116-1
RHSA-2021:3582
RHSA-2021:3903
RHSA-2021_3582
RLSA-2021:3582
SUSE-SU-2021:14768-1
SUSE-SU-2021:2425-1
SUSE-SU-2021:2439-1
SUSE-SU-2021:2440-1
SUSE-SU-2021:2462-1
SUSE-SU-2021_14768-1

Affected Products

Alt Linux
Astra Linux
Centos
Debian
Red Hat
Rocky Linux
Suse
Curl