Cleartext transmission of sensitive information in cURL - CVE-2022-30115

 

Cleartext transmission of sensitive information in cURL - CVE-2022-30115

Published: May 11, 2022


Vulnerability identifier: #VU63011
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-30115
CWE-ID: CWE-319
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an error in HSTS implementation that can allow curl to continue using HTTP protocol instead of HTTPS if the host name in the given URL used a trailing dot while not using one when it built the HSTS cache. A remote attacker with ability to intercept traffic can obtain potentially sensitive information.


Affected software

cURL
Amazon Linux AMI
Gentoo Linux
PowerSC
Oracle Solaris
Slackware Linux
Fedora
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
IBM Engineering Requirements Management DOORS Next
IBM Rational ClearCase
IBM MQ
Splunk Universal Forwarder
Splunk Enterprise
curl
net-misc/curl
PowerScale OneFS

How to mitigate CVE-2022-30115

Install updates from vendor's website.

cURL - update to 7.83.1
IBM Rational ClearCase - addressed in versions 9.0.1.14, 9.0.2.6, 9.1.0.3
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
curl - update to 7.82.0-5.fc36
net-misc/curl - update to 7.86.0
curl - update to 7.87.0-2
PowerScale OneFS - addressed in versions 9.1.0.26, 9.2.1.19, 9.4.0.10
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7

External References

Related Security Bulletins