Improper Certificate Validation in cURL - CVE-2021-22926

 

Improper Certificate Validation in cURL - CVE-2021-22926

Published: July 21, 2021


Vulnerability identifier: #VU55147
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22926
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to an error in the CURLOPT_SSLCERT option mixup with TLS library Secure Transport. A remote attacker can create a file name with the same name as the app wants to use by name, and thereby trick the application to use the file based cert instead of the one referred to by name making libcurl send the wrong client certificate in the TLS connection handshake.


Affected software

cURL
Gentoo Linux
Slackware Linux
openEuler
EasyApache
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
MySQL Server
Splunk Universal Forwarder
Splunk Enterprise
SINEC INS
IBM Cloud Private
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
curl
curl-debuginfo
libcurl
curl-debugsource
libcurl-devel
curl-help
net-misc/curl

How to mitigate CVE-2021-22926

Install updates from vendor's website.

cURL - update to 7.78.0
EasyApache - update to 4 2021-7-28
MySQL Server - update to 8.0.27
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
SINEC INS - update to 1.0.1.1
IBM Cloud Private - addressed in versions 3.2.1.2203, 3.2.2.2203
IBM Cloud Transformation Advisor - update to 3.10.0
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Watson Studio on Cloud Pak for Data - update to 5.0.3
curl - update to 7.71.1-10
curl-debuginfo - update to 7.71.1-10
libcurl - update to 7.71.1-10
curl-debugsource - update to 7.71.1-10
libcurl-devel - update to 7.71.1-10
curl-help - update to 7.71.1-10
net-misc/curl - update to 7.86.0

External References

Related Security Bulletins