Information disclosure in cURL - CVE-2020-8169
Published: June 25, 2020
Vulnerability identifier: #VU29292
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8169
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to cURL sends a DNS query with the provided credentials for HTTP authentication when processing redirects. A remote attacker that controls a DNS server can gain access to HTTP authenticated credentials.
Affected software
cURL
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Gentoo Linux
Slackware Linux
Opensuse
openEuler
Fedora
TensorFlow
jbcs-httpd24 (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-jansson (Red Hat package)
curl (Alpine package)
curl (Debian package)
jbcs-httpd24-curl (Red Hat package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
curl
libcurl-devel
libcurl
curl-help
curl-debugsource
curl-debuginfo
mingw-curl
Splunk Universal Forwarder
Splunk Enterprise
SINEC INS
SIMATIC TIM 1531 IRC
JBoss Core Services
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Gentoo Linux
Slackware Linux
Opensuse
openEuler
Fedora
TensorFlow
jbcs-httpd24 (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-jansson (Red Hat package)
curl (Alpine package)
curl (Debian package)
jbcs-httpd24-curl (Red Hat package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
curl
libcurl-devel
libcurl
curl-help
curl-debugsource
curl-debuginfo
mingw-curl
Splunk Universal Forwarder
Splunk Enterprise
SINEC INS
SIMATIC TIM 1531 IRC
JBoss Core Services
How to mitigate CVE-2020-8169
Install updates from vendor's website.
cURL - update to 7.71.0
TensorFlow - update to 2.5.0
jbcs-httpd24 (Red Hat package) - addressed in versions 1-18.el8jbcs, 1-18.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-82.el8jbcs, 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-105.el8jbcs, 1.6.3-105.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-17.el8jbcs, 1.15.7-17.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-36.el8jbcs, 2.0.8-36.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-74.el8jbcs, 2.4.37-74.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-63.GA.el8jbcs, 2.9.2-63.GA.jbcs.el7
jbcs-httpd24-jansson (Red Hat package) - addressed in versions 2.11-55.el8jbcs, 2.11-55.jbcs.el7
curl (Alpine package) - update to 7.71.0-r0
curl (Debian package) - update to 7.64.0-4+deb10u2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.77.0-2.el8jbcs, 7.77.0-2.jbcs.el7
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-20.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - update to 1.0.0-5.el8jbcs
SINEC INS - update to 1.0.1.1
jbcs-httpd24-brotli (Red Hat package) - update to 1.0.6-40.el8jbcs
jbcs-httpd24-nghttp2 (Red Hat package) - update to 1.39.2-37.el8jbcs
SIMATIC TIM 1531 IRC - update to 2.2
JBoss Core Services - update to 2.4.37 SP8
curl - addressed in versions 7.66.0-2.fc31, 7.69.1-4.fc32
libcurl-devel - update to 7.69.1-2
libcurl - update to 7.69.1-2
curl-help - update to 7.69.1-2
curl-debugsource - update to 7.69.1-2
curl-debuginfo - update to 7.69.1-2
curl - update to 7.69.1-2
mingw-curl - update to 7.71.1-1.fc32
TensorFlow - update to 2.5.0
jbcs-httpd24 (Red Hat package) - addressed in versions 1-18.el8jbcs, 1-18.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-82.el8jbcs, 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-105.el8jbcs, 1.6.3-105.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-17.el8jbcs, 1.15.7-17.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-36.el8jbcs, 2.0.8-36.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-74.el8jbcs, 2.4.37-74.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-63.GA.el8jbcs, 2.9.2-63.GA.jbcs.el7
jbcs-httpd24-jansson (Red Hat package) - addressed in versions 2.11-55.el8jbcs, 2.11-55.jbcs.el7
curl (Alpine package) - update to 7.71.0-r0
curl (Debian package) - update to 7.64.0-4+deb10u2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.77.0-2.el8jbcs, 7.77.0-2.jbcs.el7
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-20.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - update to 1.0.0-5.el8jbcs
SINEC INS - update to 1.0.1.1
jbcs-httpd24-brotli (Red Hat package) - update to 1.0.6-40.el8jbcs
jbcs-httpd24-nghttp2 (Red Hat package) - update to 1.39.2-37.el8jbcs
SIMATIC TIM 1531 IRC - update to 2.2
JBoss Core Services - update to 2.4.37 SP8
curl - addressed in versions 7.66.0-2.fc31, 7.69.1-4.fc32
libcurl-devel - update to 7.69.1-2
libcurl - update to 7.69.1-2
curl-help - update to 7.69.1-2
curl-debugsource - update to 7.69.1-2
curl-debuginfo - update to 7.69.1-2
curl - update to 7.69.1-2
mingw-curl - update to 7.71.1-1.fc32
External References
Related Security Bulletins
- Information disclosure in cURL
- Slackware Linux update for curl
- OpenSUSE Linux update for curl
- Gentoo update for cURL
- Information disclosure in curl (Alpine package)
- Debian update for curl
- Tensorflow update for third-party components
- Multiple vulnerabilities in Siemens SIMATIC TIM 1531 IRC
- Red Hat update for JBoss Core Services Pack Apache Server
- Multiple vulnerabilities in Siemens SINEC INS
- Splunk Universal Forwarder update for third-party packages
- Multiple vulnerabilities in Dell Data Protection Central
- Splunk Enterprise update for third-party packages
- openEuler 20.03 LTS update for curl-7.69.1-1
- Fedora 31 update for curl
- Fedora 32 update for curl
- Fedora 32 update for mingw-curl