An issue in libcurl's Digest authentication mechanism where certain headers were not properly cleared or validated during authentication retries, potentially leading to credential exposure in specific configurations.
The Symantec Data Loss Prevention Suite (DLP Agents and DLP Servers) does not use Digest authentication; CURLAUTH_DIGEST is never set.