Intelligence View
⚡ tsecurity.de Intelligence
CVE-2022-27776 | cURL up to 7.82.x HTTP Redirect insufficiently protected credentials
A vulnerability, which was classified as problematic, has been found in cURL up to 7.82.x. This issue affects some unknown processing of the component HTTP…
A vulnerability, which was classified as problematic, has been found in cURL up to 7.82.x. This issue affects some unknown processing of the component HTTP Redirect Handler. The manipulation leads to insufficiently protected credentials.
The identification of this vulnerability is CVE-2022-27776. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
The identification of this vulnerability is CVE-2022-27776. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
2. Cyber Threat Intelligence & Forensik
IoC Intelligence (1 Indikatoren)
CVE-2022-27776
Exploit & Remediation Lifecycle Timeline
CVE-2022-27776Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Bislang kein öffentlicher Exploit
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Upstream-Patch-Referenz vorhanden (Commit-/Advisory-Link)
Exploit Weaponization & Public PoC Radar
LOW · Index 0/100Exploit-DB
Kein EDB-EintragInteraktion
Interaktion nötigAuthentifizierung
Erforderlich3. Compliance, SLA & Vendor Adherence
BSI-Warnung (Deutschland)CVE-2022-27776
Dell Data Protection Advisor: Mehrere Schwachstellen20.01.2026Dell PowerProtect Data Domain: Mehrere Schwachstellen07.11.2024Splunk Splunk Enterprise: Mehrere Schwachstellen30.08.2023CISA-SSVC-Triage (vulnrichment)CVE-2022-27776
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2024-11-20T15:23:04.795275Z · CISA Coordinator
Advisory Radar
Offizielles Hersteller-Update verfügbar
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller hat ein verifiziertes Patch-Release herausgegeben. Sofortiges Rollout auf Test- und Produktivsystemen empfohlen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencehackerone.com
-
Web Referencesecurity.netapp.com
-
Debian Security Tracker Verifiziertdebian.org
-
Debian Security Tracker Verifiziertdebian.org
-
Web Referencelists.fedoraproject.org