XML External Entity injection in cURL - CVE-2021-22922

 

XML External Entity injection in cURL - CVE-2021-22922

Published: July 21, 2021


Vulnerability identifier: #VU55148
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22922
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.


Affected software

cURL
Gentoo Linux
Arch Linux
SUSE Manager Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE MicroOS
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
Red Hat Advanced Cluster Management for Kubernetes
EasyApache
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Splunk Universal Forwarder
Splunk Enterprise
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
curl-openssl1
libcurl4-openssl1
libcurl4-openssl1-32bit
libcurl4-openssl1-x86
libcurl4-32bit-debuginfo
libcurl4-32bit
libcurl4-debuginfo
libcurl4
libcurl-devel
curl-debugsource
curl-debuginfo
curl
libcurl4-debuginfo-32bit
libcurl-minimal
libcurl
curl (Red Hat package)
curl-help
net-misc/curl
SINEC INS
OpenShift Virtualization
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
Dell EMC VxRail Appliance

How to mitigate CVE-2021-22922

Install updates from vendor's website.

cURL - update to 7.78.0
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.1.11, 2.1.12, 2.3.3
EasyApache - update to 4 2021-7-28
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
SINEC INS - update to 1.0.1.1
OpenShift Virtualization - addressed in versions 2.6.8, 4.9.0
IBM Cloud Transformation Advisor - update to 3.10.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Watson Studio on Cloud Pak for Data - update to 5.0.3
Dell EMC VxRail Appliance - update to 7.0.203
curl-openssl1 - update to 7.37.0-70.71.1
libcurl4-openssl1 - update to 7.37.0-70.71.1
libcurl4-openssl1-32bit - update to 7.37.0-70.71.1
libcurl4-openssl1-x86 - update to 7.37.0-70.71.1
libcurl4-32bit-debuginfo - addressed in versions 7.60.0-3.47.1, 7.66.0-4.22.1
libcurl4-32bit - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl4-debuginfo - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl4 - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl-devel - addressed in versions 7.60.0-3.47.1, 7.60.0-11.23.1, 7.66.0-4.22.1
curl-debugsource - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
curl-debuginfo - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
curl - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl4-debuginfo-32bit - addressed in versions 7.60.0-4.25.1, 7.60.0-11.23.1
libcurl-minimal - addressed in versions 7.61.1-12, 7.61.1-18
curl - addressed in versions 7.61.1-12, 7.61.1-18
libcurl - addressed in versions 7.61.1-12, 7.61.1-18
libcurl-devel - addressed in versions 7.61.1-12, 7.61.1-18
curl (Red Hat package) - addressed in versions 7.61.1-12.el8_2.3, 7.61.1-18.el8_4.1
curl - addressed in versions 7.71.1-10.fc33, 7.76.1-7.fc34
libcurl - update to 7.71.1-12
curl-help - update to 7.71.1-12
curl-debugsource - update to 7.71.1-12
libcurl-devel - update to 7.71.1-12
curl-debuginfo - update to 7.71.1-12
curl - update to 7.71.1-12
net-misc/curl - update to 7.86.0

External References

Related Security Bulletins