High severity7.5NVD Advisory· Published Dec 14, 2020· Updated Jun 17, 2026
CVE-2020-8169
CVE-2020-8169
Description
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- curl/curldescription
- osv-coords4 versionspkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/curl-mini&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2
< 7.66.0-lp152.3.3.1+ 3 more
- (no CPE)range: < 7.66.0-lp152.3.3.1
- (no CPE)range: < 7.79.1-1.1
- (no CPE)range: < 7.66.0-lp152.3.3.1
- (no CPE)range: < 7.66.0-4.3.1
Patches
Vulnerability mechanics
References
5- cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfnvdPatchThird Party Advisory
- hackerone.com/reports/874778nvdExploitThird Party Advisory
- cert-portal.siemens.com/productcert/pdf/ssa-200951.pdfnvdThird Party Advisory
- curl.se/docs/CVE-2020-8169.htmlnvdVendor Advisory
- www.debian.org/security/2021/dsa-4881nvdThird Party Advisory
News mentions
0No linked articles in our index yet.