Information disclosure in cURL - CVE-2021-22876
Published: March 31, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to libcurl does not strip off user credentials from the URL when automatically populating the Referer:
HTTP request header field in outgoing HTTP requests and therefore
risks leaking sensitive data to the server that is the target of the
second HTTP request.
Affected software
Cloud Pak for Security (CP4S)
Gentoo Linux
ClevOS
Amazon Linux AMI
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
cflinuxfs3
Secured Component Verification (SCV)
IBM MaaS360 Base Module
IBM MaaS360 Ceriticate Integration Module
jbcs-httpd24 (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-jansson (Red Hat package)
curl (Alpine package)
curl (Red Hat package)
curl (Debian package)
jbcs-httpd24-curl (Red Hat package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
curl (Ubuntu package)
libcurl3 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl4-openssl1-x86
libcurl4-openssl1-32bit
libcurl4-openssl1
curl-openssl1
libcurl4 (Ubuntu package)
libcurl4-32bit-debuginfo
libcurl4-32bit
libcurl4-debuginfo
libcurl4
libcurl-devel
curl
curl-debuginfo
curl-debugsource
libcurl4-debuginfo-32bit
rh-dotnet31-curl (Red Hat package)
curl-help
libcurl
Splunk Universal Forwarder
Splunk Enterprise
SINEC INS
Migration Toolkit for Containers
Red Hat OpenShift Serverless
Red Hat Advanced Cluster Management for Kubernetes
IBM MaaS360 Cloud Extender Agent
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
JBoss Core Services
IBM MaaS360 VPN Module
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
How to mitigate CVE-2021-22876
cflinuxfs3 - update to 0.233.0
jbcs-httpd24 (Red Hat package) - addressed in versions 1-18.el8jbcs, 1-18.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-82.el8jbcs, 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-105.el8jbcs, 1.6.3-105.jbcs.el7
Cloud Pak for Security (CP4S) - update to 1.10.7.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-17.el8jbcs, 1.15.7-17.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-36.el8jbcs, 2.0.8-36.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-74.el8jbcs, 2.4.37-74.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-63.GA.el8jbcs, 2.9.2-63.GA.jbcs.el7
jbcs-httpd24-jansson (Red Hat package) - addressed in versions 2.11-55.el8jbcs, 2.11-55.jbcs.el7
curl (Alpine package) - update to 7.76.0-r0
curl (Red Hat package) - update to 7.61.1-22.el8
curl (Debian package) - update to 7.64.0-4+deb10u2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.77.0-2.el8jbcs, 7.77.0-2.jbcs.el7
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-20.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - update to 1.0.0-5.el8jbcs
SINEC INS - update to 1.0.1.1
jbcs-httpd24-brotli (Red Hat package) - update to 1.0.6-40.el8jbcs
Migration Toolkit for Containers - update to 1.5.4
Red Hat OpenShift Serverless - update to 1.20.0
jbcs-httpd24-nghttp2 (Red Hat package) - update to 1.39.2-37.el8jbcs
Secured Component Verification (SCV) - update to 1.92.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
JBoss Core Services - update to 2.4.37 SP8
IBM MaaS360 Cloud Extender Agent - update to 2.105.300.005
IBM MaaS360 Base Module - update to 2.105.300.005
IBM MaaS360 VPN Module - update to 2.105.300.005
IBM MaaS360 Ceriticate Integration Module - update to 2.105.300.005
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm7, 7.47.0-1ubuntu2.19, 7.58.0-2ubuntu3.13, 7.68.0-1ubuntu2.5, 7.68.0-1ubuntu4.3
libcurl3 (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm7, 7.47.0-1ubuntu2.19
libcurl3-nss (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm7, 7.47.0-1ubuntu2.19, 7.58.0-2ubuntu3.13, 7.68.0-1ubuntu2.5, 7.68.0-1ubuntu4.3
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm7, 7.47.0-1ubuntu2.19, 7.58.0-2ubuntu3.13, 7.68.0-1ubuntu2.5, 7.68.0-1ubuntu4.3
libcurl4-openssl1-x86 - update to 7.37.0-70.60.1
libcurl4-openssl1-32bit - update to 7.37.0-70.60.1
libcurl4-openssl1 - update to 7.37.0-70.60.1
curl-openssl1 - update to 7.37.0-70.60.1
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.13, 7.68.0-1ubuntu2.5, 7.68.0-1ubuntu4.3
libcurl4-32bit-debuginfo - addressed in versions 7.60.0-3.42.1, 7.66.0-4.14.1
libcurl4-32bit - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.15.1, 7.66.0-4.14.1
libcurl4-debuginfo - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.15.1, 7.66.0-4.14.1
libcurl4 - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.15.1, 7.66.0-4.14.1
libcurl-devel - addressed in versions 7.60.0-3.42.1, 7.60.0-11.15.1, 7.66.0-4.14.1
curl - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.15.1, 7.66.0-4.14.1
curl-debuginfo - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.15.1, 7.66.0-4.14.1
curl-debugsource - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.15.1, 7.66.0-4.14.1
libcurl4-debuginfo-32bit - addressed in versions 7.60.0-4.20.1, 7.60.0-11.15.1
rh-dotnet31-curl (Red Hat package) - update to 7.61.1-22.el7_9
curl - addressed in versions 7.69.1-8.fc32, 7.71.1-9.fc33, 7.76.0-1.fc34
curl-debugsource - update to 7.71.1-6
curl-help - update to 7.71.1-6
libcurl - update to 7.71.1-6
libcurl-devel - update to 7.71.1-6
curl-debuginfo - update to 7.71.1-6
curl - update to 7.71.1-6
Red Hat OpenStack - update to 16.2
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Debian update for curl
- Slackware Linux update for curl
- Information disclosure in curl (Alpine package)
- Multiple vulnerabilities in Cloud Foundry cflinuxfs3
- Gentoo update for cURL
- Red Hat update for JBoss Core Services Pack Apache Server
- Amazon Linux AMI update for curl
- Red Hat Enterprise Linux 8 update for curl
- Multiple vulnerabilities in Dell EMC Unity
- Multiple vulnerabilities in Siemens SINEC INS
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- Ubuntu update for curl
- Ubuntu update for curl
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender and Modules
- ClevOS update for IBM Cloud Object Storage Systems
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- .NET Core on Red Hat Enterprise Linux update for rh-dotnet31-curl
- Splunk Universal Forwarder update for third-party packages
- Splunk Enterprise update for third-party packages
- openEuler 20.03 LTS SP1 update for curl
- Multiple vulnerabilities in Dell Secured Component Verification (SCV)
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Migration Toolkit for Containers 1.5
- Fedora 32 update for curl
- Fedora 34 update for curl
- Fedora 33 update for curl
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2