Vulnerability · NVD
CVE-2025-14524
CVE-2025-14524 : medium severity (CVSS 5.3). No tracked catalog app is linked to this CVE.
- Severity (CVSS)
- 5.3
- Exploitation
- 0.7 %
- Tracked apps
- 0
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer
performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP,
POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new
target host.
Attack vector : Network
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
0.66%
exploit very unlikely
percentile 49.6%
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.