CVE-2022-27776

Publication date 27 April 2022

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

6.5 · Medium

Score breakdown

Description

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

Status

Package Ubuntu Release Status
curl 22.04 LTS jammy
Fixed 7.81.0-1ubuntu1.1
21.10 impish
Fixed 7.74.0-1.3ubuntu2.1
20.04 LTS focal
Fixed 7.68.0-1ubuntu2.10
18.04 LTS bionic
Fixed 7.58.0-2ubuntu3.17
16.04 LTS xenial Ignored end of ESM support, was ignored [regressions possible]
14.04 LTS trusty Ignored end of ESM support, was ignored [regressions possible]

Severity score breakdown

CVSS version: CVSS v3.0

Base score 6.5 · Medium

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities