Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
The bundled `curl` sources (via the Rust `curl-sys` crate) are wholly removed during the `%prep` phase to be sure we don't use them. Instead, we use the system `curl` library, so any CVE fixes only need to be made in that component on its own.