curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
- https://hackerone.com/reports/874778
- https://github.com/docker-library/faq
- https://github.com/n0-traces/cve_monitor