The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
            
            
  | 
    
Configuration 3 (hide)
            
            
  | 
    
Configuration 4 (hide)
            
            
  | 
    
Configuration 5 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2015-05-01 15:59
Updated : 2018-10-17 01:29
NVD link : CVE-2015-3153
Mitre link : CVE-2015-3153
CVE.ORG link : CVE-2015-3153
JSON object : View
Products Affected
                oracle
- enterprise_manager_ops_center
 
apple
- mac_os_x
 
canonical
- ubuntu_linux
 
haxx
- libcurl
 - curl
 
debian
- debian_linux
 
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
