CVE-2022-27776

Publication date 27 April 2022

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

6.5 · Medium

Score breakdown

Description

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

Status

Package Ubuntu Release Status
curl 22.04 LTS jammy
Fixed 7.81.0-1ubuntu1.1
21.10 impish
Fixed 7.74.0-1.3ubuntu2.1