Information disclosure in cURL - CVE-2022-27779

 

Information disclosure in cURL - CVE-2022-27779

Published: May 11, 2022


Vulnerability identifier: #VU63005
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-27779
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to libcurl wrongly allows HTTP cookies to be set for Top Level Domains (TLDs) if the host name is provided with a trailing dot. As a result, an attacker can create cookie files that are later sent to a different and unrelated site or domain.


Affected software

cURL
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
IBM Engineering Requirements Management DOORS Next
Gentoo Linux
Amazon Linux AMI
PowerSC
Slackware Linux
Fedora
IBM Rational ClearCase
Splunk Universal Forwarder
Splunk Enterprise
curl
net-misc/curl
PowerScale OneFS

How to mitigate CVE-2022-27779

Install updates from vendor's website.

cURL - update to 7.83.1
IBM Rational ClearCase - addressed in versions 9.0.1.14, 9.0.2.6, 9.1.0.3
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
curl - update to 7.82.0-5.fc36
net-misc/curl - update to 7.86.0
curl - update to 7.87.0-2
PowerScale OneFS - addressed in versions 9.1.0.26, 9.2.1.19, 9.4.0.10
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7

External References

Related Security Bulletins