CVE-2025-0167

When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:9:*:*:*:*:vmware_vsphere:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h615c:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

History

30 Jul 2025, 19:41

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Haxx
Netapp ontap
Netapp h610c
Netapp ontap Select Deploy Administration Utility
Netapp ontap Tools
Netapp h300s
Netapp solidfire \& Hci Management Node
Netapp h610c Firmware
Netapp h410c
Netapp h500s
Netapp h500s Firmware
Netapp h700s
Netapp bootstrap Os
Netapp h410s Firmware
Netapp element Software
Netapp h700s Firmware
Netapp h615c
Netapp h410c Firmware
Netapp h300s Firmware
Haxx curl
Netapp h610s
Netapp solidfire \& Hci Storage Node
Netapp h615c Firmware
Netapp h610s Firmware
Netapp
Netapp h410s
Netapp hci Compute Node
References () https://curl.se/docs/CVE-2025-0167.json - () https://curl.se/docs/CVE-2025-0167.json - Vendor Advisory
References () https://hackerone.com/reports/2917232 - () https://hackerone.com/reports/2917232 - Exploit, Issue Tracking, Third Party Advisory
References () https://curl.se/docs/CVE-2025-0167.html - () https://curl.se/docs/CVE-2025-0167.html - Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20250306-0008/ - () https://security.netapp.com/advisory/ntap-20250306-0008/ - Third Party Advisory
CPE cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h615c:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:9:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*

07 Mar 2025, 01:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250306-0008/ -
References () https://curl.se/docs/CVE-2025-0167.html - () https://curl.se/docs/CVE-2025-0167.html -

05 Feb 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-05 10:15

Updated : 2025-07-30 19:41


NVD link : CVE-2025-0167

Mitre link : CVE-2025-0167


JSON object : View

Products Affected

netapp

  • h615c_firmware
  • h610c
  • h615c
  • h300s
  • h410s_firmware
  • ontap
  • h410s
  • h500s
  • h610s
  • h700s
  • ontap_tools
  • solidfire_\&_hci_management_node
  • h300s_firmware
  • h410c_firmware
  • h410c
  • bootstrap_os
  • h610s_firmware
  • h700s_firmware
  • solidfire_\&_hci_storage_node
  • h500s_firmware
  • ontap_select_deploy_administration_utility
  • h610c_firmware
  • element_software
  • hci_compute_node

haxx

  • curl