endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

CVE-2022-27776 | curl (CWE-0) #2

Open mgulter opened 2 years ago

mgulter commented 2 years ago

A medium severity vulnerability has been discovered in your project.

Project Name: IssueTest

Scanner Name: trivy

CVE ID: CVE-2022-27776

Target: nginx:latest (debian 11.3)

Packages:

References:

Tool Description: A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

Custom Description: test assignment