Information disclosure in cURL - CVE-2023-46218

 

Information disclosure in cURL - CVE-2023-46218

Published: December 6, 2023


Vulnerability identifier: #VU83900
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46218
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to an error in curl that allows a malicious HTTP server to set "super cookies" that are then passed back to more origins than what is otherwise allowed or possible. A remote attacker can force curl to send such cookie to different and unrelated sites and domains.


Affected software

cURL
Integrated Data protection Appliance (IDPA)
IBM Qradar SIEM
Data Protection Search
Amazon Linux AMI
Oracle Linux
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
BIG-IP Next CNF
BIG-IP Next SPK
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Red Hat OpenShift Builds
Data Lakehouse
Migration Toolkit for Runtimes
Service Interconnect
Service Telemetry Framework
Oracle Communications Converged Charging System
Cryostat
IBM MQ Operator
OpenShift Logging
Red Hat Migration Toolkit for Applications
Oracle Communications Diameter Signaling Router
Oracle HTTP Server
IBM Cloud Transformation Advisor
IBM Cloud Object Storage Systems
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
EasyApache
App Connect Enterprise Certified Container
IBM Security Verify Governance
IBM QRadar WinCollect Agent
Red Hat OpenStack
EMC NetWorker Server
Juniper Cloud Native Router
Telemetry Dashboard
Dell EMC PowerProtect Data Protection
Liquidware
SmartFabric OS10
webMethods Managed File Transfer
Citrix Workspace App
Webex App VDI
Storage Copy Data Management
Cloud Pak for Network Automation
Enterprise SONiC
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Total Storage Service Console (TSSC) / TS4500 IMC
Storage Protect Plus Server
NetWorker Management Console (NMC)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Nessus Network Monitor
VMware Horizon Client
Red Hat OpenShift GitOps
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Supplied MQ Advanced Queue Manager Container images
LANTIME Operating System Firmware (LTOS)
BIG-IP
PowerScale OneFS
Junos cRPD
Juniper Secure Analytics (JSA)
Dell EMC NetWorker vProxy
Red Hat Single Sign-On
BIG-IQ Centralized Management
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libcurl3-gnutls (Ubuntu package)
curl (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl3 (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libcurl-devel
curl
curl-debuginfo
libcurl4
curl-debugsource
libcurl4-debuginfo
libcurl4-32bit-debuginfo
libcurl4-32bit
curl (Red Hat package)
curl-doc
libcurl-minimal
libcurl
curl-minimal
curl-help
curl (Debian package)
libcurl4-debuginfo-32bit
libcurl4-64bit-debuginfo
libcurl4-64bit
libcurl-devel-32bit
libcurl-devel-64bit
jbcs-httpd24-curl (Red Hat package)
net-misc/curl
Cisco Jabber
BIG-IP Next Central Manager
Cisco Webex Meetings
JBoss Core Services
AMQ Broker

How to mitigate CVE-2023-46218

Install updates from vendor's website.

cURL - update to 8.5.0
Red Hat OpenShift Builds - update to 1.0.1
Data Lakehouse - update to 1.1.0.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Migration Toolkit for Runtimes - update to 1.2.5
OpenShift API for Data Protection (OADP) - update to 1.3.1
Service Interconnect - update to 1.5.3
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.10.4, 1.11, 1.11.3, 1.12.1
IBM MQ Operator - addressed in versions 2.0.21, 3.1.2
OpenShift Service Mesh - update to 2.5.1
Dell EMC PowerProtect Data Protection - update to 2.7.8
Red Hat OpenShift Container Platform - addressed in versions 4.12.58, 4.14.17, 4.15.0, 4.15.3
OpenShift Logging - addressed in versions 5.6.18, 5.7.13, 5.8.6
Nessus Network Monitor - update to 6.4.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Red Hat Migration Toolkit for Applications - addressed in versions 7.0.2, 7.0.3
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat Single Sign-On - update to 7.6.8
SmartFabric OS10 - addressed in versions 10.5.5.9, 10.5.6.1
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
BIG-IP Next Central Manager - update to 20.1.0
BIG-IP - update to 20.1.0
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libcurl3-gnutls (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
curl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
libcurl3-nss (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
libcurl4 (Ubuntu package) - addressed in versions Ubuntu Pro, 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
libcurl3 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-35.el7jbcs, 0.4.10-35.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-20.el7jbcs, 1.0.0-20.el8jbcs
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.20-3.el7jbcs, 1.3.20-3.el8jbcs
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-104.el7jbcs, 1.6.1-104.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-36.el7jbcs, 1.15.19-36.el8jbcs
Storage Copy Data Management - update to 2.2.24.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-4.el7jbcs, 2.4.24-4.el8jbcs
JBoss Core Services - update to 2.4.57 SP3
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-9.el7jbcs, 2.4.57-9.el8jbcs
Cloud Pak for Network Automation - update to 2.7
Integrated Data protection Appliance (IDPA) - update to 2.7.8 with DP Search 19.6.6
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-34.el7jbcs, 2.9.3-34.el8jbcs
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Cloud Object Storage Systems - addressed in versions 3.18.0.40, 3.18.1.45
Enterprise SONiC - update to 4.2.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
EasyApache - update to 4 2023-12-13
App Connect Enterprise Certified Container - addressed in versions 5.0.17, 11.5.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
AMQ Broker - update to 7.12.0
libcurl-devel - addressed in versions 7.60.0-150000.56.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl - addressed in versions 7.60.0-150000.56.1, 7.66.0-150200.4.63.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl-debuginfo - addressed in versions 7.60.0-150000.56.1, 7.66.0-150200.4.63.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl4 - addressed in versions 7.60.0-150000.56.1, 7.66.0-150200.4.63.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl-debugsource - addressed in versions 7.60.0-150000.56.1, 7.66.0-150200.4.63.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl4-debuginfo - addressed in versions 7.60.0-150000.56.1, 7.66.0-150200.4.63.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl4-32bit-debuginfo - addressed in versions 7.60.0-150000.56.1, 8.0.1-150400.5.36.1
libcurl4-32bit - addressed in versions 7.60.0-150000.56.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl (Red Hat package) - addressed in versions 7.61.1-30.el8_8.9, 7.61.1-33.el8_9.5, 7.76.1-14.el9_0.11, 7.76.1-23.el9_2.6, 7.76.1-26.el9_3.3
curl-doc - addressed in versions 7.61.1-34.0.2, 8.4.0-6
libcurl-minimal - addressed in versions 7.61.1-34.0.2, 8.4.0-6
libcurl-devel - addressed in versions 7.61.1-34.0.2, 8.4.0-6
libcurl - addressed in versions 7.61.1-34.0.2, 8.4.0-6
curl-minimal - addressed in versions 7.61.1-34.0.2, 8.4.0-6
curl - addressed in versions 7.61.1-34.0.2, 8.4.0-6
curl-help - update to 7.71.1-32
libcurl-devel - update to 7.71.1-32
libcurl - update to 7.71.1-32
curl-debugsource - update to 7.71.1-32
curl-debuginfo - update to 7.71.1-32
curl - update to 7.71.1-32
curl (Debian package) - addressed in versions 7.74.0-1.3+deb11u11, 7.88.1-10+deb12u5
curl - addressed in versions 8.0.1-6.fc38, 8.2.1-4.fc39
libcurl4-debuginfo-32bit - update to 8.0.1-11.80.1
libcurl4-64bit-debuginfo - update to 8.0.1-150400.5.36.1
libcurl4-64bit - update to 8.0.1-150400.5.36.1
libcurl-devel-32bit - update to 8.0.1-150400.5.36.1
libcurl-devel-64bit - update to 8.0.1-150400.5.36.1
Storage Protect Client - update to 8.1.23.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.24.0
curl - update to 8.5.0-1
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.6.0-3.el7jbcs, 8.6.0-3.el8jbcs
net-misc/curl - update to 8.7.1
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.17-r1, 9.3.5.1-r1
PowerScale OneFS - addressed in versions 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0
Total Storage Service Console (TSSC) / TS4500 IMC - update to 9.4.31
IBM Security Verify Governance - update to 10.0.2.0.4
IBM QRadar WinCollect Agent - update to 10.1.9
Storage Protect Plus Server - update to 10.1.16.3
Red Hat OpenStack - update to 16.2
Data Protection Search - update to 19.6.6
EMC NetWorker Server - update to 19.10.0.5
NetWorker Management Console (NMC) - update to 19.10.0.5
Dell EMC NetWorker vProxy - addressed in versions 19.11.0.5, 19.12.0.1
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins