Cleartext transmission of sensitive information in cURL - CVE-2023-23914

 

Cleartext transmission of sensitive information in cURL - CVE-2023-23914

Published: February 16, 2023


Vulnerability identifier: #VU72335
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23914
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to state issues when handling multiple requests, which results in ignoring HSTS support. A remote attacker can perform MitM attack.

Affected software

cURL
PowerSC
Amazon Linux AMI
Gentoo Linux
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Oracle Solaris
Slackware Linux
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Ubuntu
Junos OS Evolved
openEuler
Fedora
Junos OS
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Telemetry Dashboard
Liquidware
IBM Engineering Requirements Management DOORS Next
Citrix Workspace App
Webex App VDI
cflinuxfs3
ObjectScale
Dell EMC Streaming Data Platform
Platform Automation Toolkit
Dell PowerProtect Cyber Recovery
IBM Spectrum Copy Data Management
IBM QRadar WinCollect Agent
Oracle HTTP Server
IBM MQ Operator
IBM Safer Payments
IBM Spectrum Protect Plus
JBoss Core Services
Oracle Healthcare Translational Research
LANTIME Operating System Firmware (LTOS)
Splunk Universal Forwarder
Splunk Enterprise
Oracle Enterprise Manager Ops Center
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
curl (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
curl
libcurl
curl-debugsource
curl-debuginfo
libcurl-devel
curl-help
libcurl4
libcurl4-debuginfo
libcurl-devel-32bit
libcurl4-32bit
libcurl4-32bit-debuginfo
jbcs-httpd24-curl (Red Hat package)
net-misc/curl

How to mitigate CVE-2023-23914

Install updates from vendor's website.

cURL - update to 7.88.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
IBM Spectrum Copy Data Management - update to 2.2.20.0
JBoss Core Services - update to 2.4.51 SP2
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
LANTIME Operating System Firmware (LTOS) - update to 7.06.012
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
IBM QRadar WinCollect Agent - update to 10.1.3
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Junos OS Evolved - addressed in versions 21.4R3-S4-EVO, 22.1R3-S4-EVO, 22.3R3-S1-EVO, 22.4R2-S1-EVO, 23.2R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-33.el7jbcs, 0.4.10-33.el8jbcs
cflinuxfs3 - update to 0.353.0
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-18.el7jbcs, 1.0.0-18.el8jbcs
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.18-2.el7jbcs, 1.3.18-2.el8jbcs
ObjectScale - update to 1.4.0
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-101.el7jbcs, 1.6.1-101.el8jbcs
Dell EMC Streaming Data Platform - update to 1.7.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-23.el7jbcs, 1.15.19-23.el8jbcs
IBM MQ Operator - addressed in versions 2.0.10, 2.3.2
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.0-20.el7jbcs, 2.4.0-20.el8jbcs
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.51-39.el7jbcs, 2.4.51-39.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-24.el7jbcs, 2.9.3-24.el8jbcs
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.1
IBM Safer Payments - addressed in versions 6.4.2.03, 6.5.0.01
curl (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.23, 7.68.0-1ubuntu2.16, 7.81.0-1ubuntu1.8, 7.85.0-1ubuntu0.3
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.23, 7.68.0-1ubuntu2.16, 7.81.0-1ubuntu1.8, 7.85.0-1ubuntu0.3
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.23, 7.68.0-1ubuntu2.16, 7.81.0-1ubuntu1.8, 7.85.0-1ubuntu0.3
libcurl3-nss (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.23, 7.68.0-1ubuntu2.16, 7.81.0-1ubuntu1.8, 7.85.0-1ubuntu0.3
curl - update to 7.79.1-14
libcurl - update to 7.79.1-14
curl-debugsource - update to 7.79.1-14
curl-debuginfo - update to 7.79.1-14
libcurl-devel - update to 7.79.1-14
curl-help - update to 7.79.1-14
curl - update to 7.79.1-150400.5.15.1
libcurl4 - update to 7.79.1-150400.5.15.1
curl-debugsource - update to 7.79.1-150400.5.15.1
curl-debuginfo - update to 7.79.1-150400.5.15.1
libcurl4-debuginfo - update to 7.79.1-150400.5.15.1
libcurl-devel - update to 7.79.1-150400.5.15.1
libcurl-devel-32bit - update to 7.79.1-150400.5.15.1
libcurl4-32bit - update to 7.79.1-150400.5.15.1
libcurl4-32bit-debuginfo - update to 7.79.1-150400.5.15.1
curl - update to 7.85.0-6.fc37
curl - update to 7.88.0
curl - update to 7.88.0-1
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.0.1-1.el7jbcs, 8.0.1-1.el8jbcs
net-misc/curl - update to 8.3.0-r2
IBM Spectrum Protect Plus - update to 10.1.15
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
Junos OS - addressed in versions 23.4R1-S1, 23.4R2, 24.1R1

External References

Related Security Bulletins