VDB
CVE-2022-27774
CVE-2022-27774
PUBLISHED
EPSS 0.31% · 54.2th percentile
Risk Scores
EPSS Score
0.31%
54.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amazon | curl |
Exploit Intelligence
- Trailing-Dot Hostname in Redirect Silently Strips Client Certificate and Auth Credentials (hackerone)
- Trailing-Dot Hostname in Redirect Silently Strips Client Certificate and Auth Credentials (hackerone)
- CURLOPT_COOKIE leaked to cross-origin redirect target — CURLOPT_UNRESTRICTED_AUTH bypass for the STRING_COOKIE path (hackerone)
- CURLOPT_COOKIE leaked to cross-origin redirect target — CURLOPT_UNRESTRICTED_AUTH bypass for the STRING_COOKIE path (hackerone)
- Credentials forwarded to HTTP after HTTPS→HTTP same-port redirect — url_set_data_creds uses scheme-blind comparator (hackerone)
- Credentials forwarded to HTTP after HTTPS→HTTP same-port redirect — url_set_data_creds uses scheme-blind comparator (hackerone)
- Credentials forwarded to HTTP after HTTPS→HTTP same-port redirect — url_set_data_creds uses scheme-blind comparator (hackerone)
- https://hackerone.com/reports/1543773 (nist-nvd)
- CVE-2008-5161 OpenSSH 4.7p1 Audit Helper Automates version checking and credential auditing of legacy OpenSSH 4.7p1 (Debian-8ubuntu1) targets by driving Metasploit’s auxiliary/scanner/ssh/ssh_login module from Python via pwntools. (github-poc)
- CVE-2008-5161 OpenSSH 4.7p1 Audit Helper Automates version checking and credential auditing of legacy OpenSSH 4.7p1 (Debian-8ubuntu1) targets by driving Metasploit’s auxiliary/scanner/ssh/ssh_login module from Python via pwntools. (github-poc)
…and 34 more exploits
Timeline
- CVE Published
- Apr 27, 2022 PoC Published
- Apr 29, 2022 PoC Published
- Jun 2, 2022 EPSS Score
- Jul 22, 2022 EPSS Score
- Sep 8, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 14, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 21, 2023 EPSS Score
- May 9, 2023 EPSS Score
- Jun 26, 2023 EPSS Score
References
- ALAS-2022-1646: curl (medium) advisory