Information disclosure in cURL - CVE-2021-22876

 

Information disclosure in cURL - CVE-2021-22876

Published: March 31, 2021


Vulnerability identifier: #VU51821
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22876
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.


Affected software

cURL
Cloud Pak for Security (CP4S)
Gentoo Linux
ClevOS
Amazon Linux AMI
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
cflinuxfs3
Secured Component Verification (SCV)
IBM MaaS360 Base Module
IBM MaaS360 Ceriticate Integration Module
jbcs-httpd24 (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-jansson (Red Hat package)
curl (Alpine package)
curl (Red Hat package)
curl (Debian package)
jbcs-httpd24-curl (Red Hat package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
curl (Ubuntu package)
libcurl3 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl4-openssl1-x86
libcurl4-openssl1-32bit
libcurl4-openssl1
curl-openssl1
libcurl4 (Ubuntu package)
libcurl4-32bit-debuginfo
libcurl4-32bit
libcurl4-debuginfo
libcurl4
libcurl-devel
curl
curl-debuginfo
curl-debugsource
libcurl4-debuginfo-32bit
rh-dotnet31-curl (Red Hat package)
curl-help
libcurl
Splunk Universal Forwarder
Splunk Enterprise
SINEC INS
Migration Toolkit for Containers
Red Hat OpenShift Serverless
Red Hat Advanced Cluster Management for Kubernetes
IBM MaaS360 Cloud Extender Agent
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
JBoss Core Services
IBM MaaS360 VPN Module
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)

How to mitigate CVE-2021-22876

Install updates from vendor's website.

cURL - update to 7.76.0
cflinuxfs3 - update to 0.233.0
jbcs-httpd24 (Red Hat package) - addressed in versions 1-18.el8jbcs, 1-18.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-82.el8jbcs, 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-105.el8jbcs, 1.6.3-105.jbcs.el7
Cloud Pak for Security (CP4S) - update to 1.10.7.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-17.el8jbcs, 1.15.7-17.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-36.el8jbcs, 2.0.8-36.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-74.el8jbcs, 2.4.37-74.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-63.GA.el8jbcs, 2.9.2-63.GA.jbcs.el7
jbcs-httpd24-jansson (Red Hat package) - addressed in versions 2.11-55.el8jbcs, 2.11-55.jbcs.el7
curl (Alpine package) - update to 7.76.0-r0
curl (Red Hat package) - update to 7.61.1-22.el8
curl (Debian package) - update to 7.64.0-4+deb10u2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.77.0-2.el8jbcs, 7.77.0-2.jbcs.el7
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-20.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - update to 1.0.0-5.el8jbcs
SINEC INS - update to 1.0.1.1
jbcs-httpd24-brotli (Red Hat package) - update to 1.0.6-40.el8jbcs
Migration Toolkit for Containers - update to 1.5.4
Red Hat OpenShift Serverless - update to 1.20.0
jbcs-httpd24-nghttp2 (Red Hat package) - update to 1.39.2-37.el8jbcs
Secured Component Verification (SCV) - update to 1.92.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
JBoss Core Services - update to 2.4.37 SP8
IBM MaaS360 Cloud Extender Agent - update to 2.105.300.005
IBM MaaS360 Base Module - update to 2.105.300.005
IBM MaaS360 VPN Module - update to 2.105.300.005
IBM MaaS360 Ceriticate Integration Module - update to 2.105.300.005
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm7, 7.47.0-1ubuntu2.19, 7.58.0-2ubuntu3.13, 7.68.0-1ubuntu2.5, 7.68.0-1ubuntu4.3
libcurl3 (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm7, 7.47.0-1ubuntu2.19
libcurl3-nss (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm7, 7.47.0-1ubuntu2.19, 7.58.0-2ubuntu3.13, 7.68.0-1ubuntu2.5, 7.68.0-1ubuntu4.3
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm7, 7.47.0-1ubuntu2.19, 7.58.0-2ubuntu3.13, 7.68.0-1ubuntu2.5, 7.68.0-1ubuntu4.3
libcurl4-openssl1-x86 - update to 7.37.0-70.60.1
libcurl4-openssl1-32bit - update to 7.37.0-70.60.1
libcurl4-openssl1 - update to 7.37.0-70.60.1
curl-openssl1 - update to 7.37.0-70.60.1
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.13, 7.68.0-1ubuntu2.5, 7.68.0-1ubuntu4.3
libcurl4-32bit-debuginfo - addressed in versions 7.60.0-3.42.1, 7.66.0-4.14.1
libcurl4-32bit - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.15.1, 7.66.0-4.14.1
libcurl4-debuginfo - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.15.1, 7.66.0-4.14.1
libcurl4 - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.15.1, 7.66.0-4.14.1
libcurl-devel - addressed in versions 7.60.0-3.42.1, 7.60.0-11.15.1, 7.66.0-4.14.1
curl - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.15.1, 7.66.0-4.14.1
curl-debuginfo - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.15.1, 7.66.0-4.14.1
curl-debugsource - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.15.1, 7.66.0-4.14.1
libcurl4-debuginfo-32bit - addressed in versions 7.60.0-4.20.1, 7.60.0-11.15.1
rh-dotnet31-curl (Red Hat package) - update to 7.61.1-22.el7_9
curl - addressed in versions 7.69.1-8.fc32, 7.71.1-9.fc33, 7.76.0-1.fc34
curl-debugsource - update to 7.71.1-6
curl-help - update to 7.71.1-6
libcurl - update to 7.71.1-6
libcurl-devel - update to 7.71.1-6
curl-debuginfo - update to 7.71.1-6
curl - update to 7.71.1-6
Red Hat OpenStack - update to 16.2

External References

Related Security Bulletins