XML External Entity injection in cURL - CVE-2021-22922
Published: July 21, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
Affected software
Gentoo Linux
Arch Linux
SUSE Manager Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE MicroOS
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
Red Hat Advanced Cluster Management for Kubernetes
EasyApache
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Splunk Universal Forwarder
Splunk Enterprise
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
curl-openssl1
libcurl4-openssl1
libcurl4-openssl1-32bit
libcurl4-openssl1-x86
libcurl4-32bit-debuginfo
libcurl4-32bit
libcurl4-debuginfo
libcurl4
libcurl-devel
curl-debugsource
curl-debuginfo
curl
libcurl4-debuginfo-32bit
libcurl-minimal
libcurl
curl (Red Hat package)
curl-help
net-misc/curl
SINEC INS
OpenShift Virtualization
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
Dell EMC VxRail Appliance
How to mitigate CVE-2021-22922
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.1.11, 2.1.12, 2.3.3
EasyApache - update to 4 2021-7-28
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
SINEC INS - update to 1.0.1.1
OpenShift Virtualization - addressed in versions 2.6.8, 4.9.0
IBM Cloud Transformation Advisor - update to 3.10.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Watson Studio on Cloud Pak for Data - update to 5.0.3
Dell EMC VxRail Appliance - update to 7.0.203
curl-openssl1 - update to 7.37.0-70.71.1
libcurl4-openssl1 - update to 7.37.0-70.71.1
libcurl4-openssl1-32bit - update to 7.37.0-70.71.1
libcurl4-openssl1-x86 - update to 7.37.0-70.71.1
libcurl4-32bit-debuginfo - addressed in versions 7.60.0-3.47.1, 7.66.0-4.22.1
libcurl4-32bit - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl4-debuginfo - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl4 - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl-devel - addressed in versions 7.60.0-3.47.1, 7.60.0-11.23.1, 7.66.0-4.22.1
curl-debugsource - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
curl-debuginfo - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
curl - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl4-debuginfo-32bit - addressed in versions 7.60.0-4.25.1, 7.60.0-11.23.1
libcurl-minimal - addressed in versions 7.61.1-12, 7.61.1-18
curl - addressed in versions 7.61.1-12, 7.61.1-18
libcurl - addressed in versions 7.61.1-12, 7.61.1-18
libcurl-devel - addressed in versions 7.61.1-12, 7.61.1-18
curl (Red Hat package) - addressed in versions 7.61.1-12.el8_2.3, 7.61.1-18.el8_4.1
curl - addressed in versions 7.71.1-10.fc33, 7.76.1-7.fc34
libcurl - update to 7.71.1-12
curl-help - update to 7.71.1-12
curl-debugsource - update to 7.71.1-12
libcurl-devel - update to 7.71.1-12
curl-debuginfo - update to 7.71.1-12
curl - update to 7.71.1-12
net-misc/curl - update to 7.86.0
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Slackware Linux update for curl
- Arch Linux update for curl
- cPanel EasyApache 4 update for libcurl
- Red Hat Enterprise Linux 8.4 update for curl
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes
- Red Hat Enterprise Linux 8.2 update for curl
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.3
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.1
- Multiple vulnerabilities in Red Hat OpenShift Virtualization
- Multiple vulnerabilities in Red Hat OpenShift Virtualization
- Multiple vulnerabilities in Siemens SINEC INS
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Gentoo update for curl
- Splunk Universal Forwarder update for third-party packages
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- openEuler update for curl
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Fedora 34 update for curl
- Fedora 33 update for curl
- Multiple vulnerabilities in IBM Watson Studio on Cloud Pak for Data - Execution Engine for Apache Hadoop
- Anolis OS update for curl (Anolis OS 8.4)
- Anolis OS update for curl (Anolis OS 8.2)