Information disclosure in cURL - CVE-2023-46218
Published: December 6, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an error in curl that allows a malicious HTTP server to set "super cookies" that are then passed back to more origins than what is otherwise allowed or possible. A remote attacker can force curl to send such cookie to different and unrelated sites and domains.
Affected software
Integrated Data protection Appliance (IDPA)
IBM Qradar SIEM
Data Protection Search
Amazon Linux AMI
Oracle Linux
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
BIG-IP Next CNF
BIG-IP Next SPK
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Red Hat OpenShift Builds
Data Lakehouse
Migration Toolkit for Runtimes
Service Interconnect
Service Telemetry Framework
Oracle Communications Converged Charging System
Cryostat
IBM MQ Operator
OpenShift Logging
Red Hat Migration Toolkit for Applications
Oracle Communications Diameter Signaling Router
Oracle HTTP Server
IBM Cloud Transformation Advisor
IBM Cloud Object Storage Systems
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
EasyApache
App Connect Enterprise Certified Container
IBM Security Verify Governance
IBM QRadar WinCollect Agent
Red Hat OpenStack
EMC NetWorker Server
Juniper Cloud Native Router
Telemetry Dashboard
Dell EMC PowerProtect Data Protection
Liquidware
SmartFabric OS10
webMethods Managed File Transfer
Citrix Workspace App
Webex App VDI
Storage Copy Data Management
Cloud Pak for Network Automation
Enterprise SONiC
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Total Storage Service Console (TSSC) / TS4500 IMC
Storage Protect Plus Server
NetWorker Management Console (NMC)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Nessus Network Monitor
VMware Horizon Client
Red Hat OpenShift GitOps
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Supplied MQ Advanced Queue Manager Container images
LANTIME Operating System Firmware (LTOS)
BIG-IP
PowerScale OneFS
Junos cRPD
Juniper Secure Analytics (JSA)
Dell EMC NetWorker vProxy
Red Hat Single Sign-On
BIG-IQ Centralized Management
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libcurl3-gnutls (Ubuntu package)
curl (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl3 (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libcurl-devel
curl
curl-debuginfo
libcurl4
curl-debugsource
libcurl4-debuginfo
libcurl4-32bit-debuginfo
libcurl4-32bit
curl (Red Hat package)
curl-doc
libcurl-minimal
libcurl
curl-minimal
curl-help
curl (Debian package)
libcurl4-debuginfo-32bit
libcurl4-64bit-debuginfo
libcurl4-64bit
libcurl-devel-32bit
libcurl-devel-64bit
jbcs-httpd24-curl (Red Hat package)
net-misc/curl
Cisco Jabber
BIG-IP Next Central Manager
Cisco Webex Meetings
JBoss Core Services
AMQ Broker
How to mitigate CVE-2023-46218
Red Hat OpenShift Builds - update to 1.0.1
Data Lakehouse - update to 1.1.0.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Migration Toolkit for Runtimes - update to 1.2.5
OpenShift API for Data Protection (OADP) - update to 1.3.1
Service Interconnect - update to 1.5.3
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.10.4, 1.11, 1.11.3, 1.12.1
IBM MQ Operator - addressed in versions 2.0.21, 3.1.2
OpenShift Service Mesh - update to 2.5.1
Dell EMC PowerProtect Data Protection - update to 2.7.8
Red Hat OpenShift Container Platform - addressed in versions 4.12.58, 4.14.17, 4.15.0, 4.15.3
OpenShift Logging - addressed in versions 5.6.18, 5.7.13, 5.8.6
Nessus Network Monitor - update to 6.4.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Red Hat Migration Toolkit for Applications - addressed in versions 7.0.2, 7.0.3
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat Single Sign-On - update to 7.6.8
SmartFabric OS10 - addressed in versions 10.5.5.9, 10.5.6.1
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
BIG-IP Next Central Manager - update to 20.1.0
BIG-IP - update to 20.1.0
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libcurl3-gnutls (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
curl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
libcurl3-nss (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
libcurl4 (Ubuntu package) - addressed in versions Ubuntu Pro, 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
libcurl3 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-35.el7jbcs, 0.4.10-35.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-20.el7jbcs, 1.0.0-20.el8jbcs
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.20-3.el7jbcs, 1.3.20-3.el8jbcs
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-104.el7jbcs, 1.6.1-104.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-36.el7jbcs, 1.15.19-36.el8jbcs
Storage Copy Data Management - update to 2.2.24.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-4.el7jbcs, 2.4.24-4.el8jbcs
JBoss Core Services - update to 2.4.57 SP3
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-9.el7jbcs, 2.4.57-9.el8jbcs
Cloud Pak for Network Automation - update to 2.7
Integrated Data protection Appliance (IDPA) - update to 2.7.8 with DP Search 19.6.6
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-34.el7jbcs, 2.9.3-34.el8jbcs
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Cloud Object Storage Systems - addressed in versions 3.18.0.40, 3.18.1.45
Enterprise SONiC - update to 4.2.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
EasyApache - update to 4 2023-12-13
App Connect Enterprise Certified Container - addressed in versions 5.0.17, 11.5.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
AMQ Broker - update to 7.12.0
libcurl-devel - addressed in versions 7.60.0-150000.56.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl - addressed in versions 7.60.0-150000.56.1, 7.66.0-150200.4.63.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl-debuginfo - addressed in versions 7.60.0-150000.56.1, 7.66.0-150200.4.63.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl4 - addressed in versions 7.60.0-150000.56.1, 7.66.0-150200.4.63.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl-debugsource - addressed in versions 7.60.0-150000.56.1, 7.66.0-150200.4.63.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl4-debuginfo - addressed in versions 7.60.0-150000.56.1, 7.66.0-150200.4.63.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl4-32bit-debuginfo - addressed in versions 7.60.0-150000.56.1, 8.0.1-150400.5.36.1
libcurl4-32bit - addressed in versions 7.60.0-150000.56.1, 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl (Red Hat package) - addressed in versions 7.61.1-30.el8_8.9, 7.61.1-33.el8_9.5, 7.76.1-14.el9_0.11, 7.76.1-23.el9_2.6, 7.76.1-26.el9_3.3
curl-doc - addressed in versions 7.61.1-34.0.2, 8.4.0-6
libcurl-minimal - addressed in versions 7.61.1-34.0.2, 8.4.0-6
libcurl-devel - addressed in versions 7.61.1-34.0.2, 8.4.0-6
libcurl - addressed in versions 7.61.1-34.0.2, 8.4.0-6
curl-minimal - addressed in versions 7.61.1-34.0.2, 8.4.0-6
curl - addressed in versions 7.61.1-34.0.2, 8.4.0-6
curl-help - update to 7.71.1-32
libcurl-devel - update to 7.71.1-32
libcurl - update to 7.71.1-32
curl-debugsource - update to 7.71.1-32
curl-debuginfo - update to 7.71.1-32
curl - update to 7.71.1-32
curl (Debian package) - addressed in versions 7.74.0-1.3+deb11u11, 7.88.1-10+deb12u5
curl - addressed in versions 8.0.1-6.fc38, 8.2.1-4.fc39
libcurl4-debuginfo-32bit - update to 8.0.1-11.80.1
libcurl4-64bit-debuginfo - update to 8.0.1-150400.5.36.1
libcurl4-64bit - update to 8.0.1-150400.5.36.1
libcurl-devel-32bit - update to 8.0.1-150400.5.36.1
libcurl-devel-64bit - update to 8.0.1-150400.5.36.1
Storage Protect Client - update to 8.1.23.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.24.0
curl - update to 8.5.0-1
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.6.0-3.el7jbcs, 8.6.0-3.el8jbcs
net-misc/curl - update to 8.7.1
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.17-r1, 9.3.5.1-r1
PowerScale OneFS - addressed in versions 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0
Total Storage Service Console (TSSC) / TS4500 IMC - update to 9.4.31
IBM Security Verify Governance - update to 10.0.2.0.4
IBM QRadar WinCollect Agent - update to 10.1.9
Storage Protect Plus Server - update to 10.1.16.3
Red Hat OpenStack - update to 16.2
Data Protection Search - update to 19.6.6
EMC NetWorker Server - update to 19.10.0.5
NetWorker Management Console (NMC) - update to 19.10.0.5
Dell EMC NetWorker vProxy - addressed in versions 19.11.0.5, 19.12.0.1
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Ubuntu update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- Fedora 39 update for curl
- Fedora 38 update for curl
- SUSE update for curl
- cPanel EasyApache update for libcurl
- Debian update for curl
- Red Hat Enterprise Linux 9.0 Extended Update Support update for curl
- Red Hat Enterprise Linux 9.2 Extended Update Support update for curl
- Red Hat Enterprise Linux 8.8 Extended Update Support update for curl
- Multiple vulnerabilities in IBM Cloud Object System
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- Ubuntu update for curl
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Red Hat Enterprise Linux 9 update for curl
- openEuler update for curl
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.15
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Multiple vulnerabilities in Red Hat JBoss Core Services for RHEL 7 and 8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Migration Toolkit for Applications 7.0
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Red Hat Enterprise Linux 8 update for curl
- Multiple vulnerabilities in Red Hat OpenShift Builds
- Multiple vulnerabilities in Logging Subsystem 5.8 for Red Hat OpenShift for RHEL 9
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in Oracle HTTP Server
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in Red Hat Service Interconnect 1.5
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh Containers 2.5
- Multiple vulnerabilities in Dell Networking OS10
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.10
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Tenable Nessus Network Monitor update for third-party components
- Multiple vulnerabilities in Red Hat build of Cryostat 2 on RHEL 8
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in Dell Enterprise SONiC Distribution
- Multiple vulnerabilities in Dell SmartFabric OS10
- Multiple vulnerabilities in OpenShift Logging 5.7
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in AMQ Broker 7.12
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM Storage Protect Client
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Multiple vulnerabilities in Oracle Communications Converged Charging System
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Amazon Linux AMI update for curl
- Amazon Linux AMI update for curl
- Gentoo update for curl
- Multiple vulnerabilities in IBM Storage Protect Plus
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Multiple vulnerabilities in IBM Storage Protect for Virtual Environments: Data Protection for Microsoft Hyper-V
- Multiple vulnerabilities in Dell NetWorker And NetWorker Management Console
- Multiple vulnerabilities in IBM Total Storage Service Console (TSSC) / TS4500 IMC
- F5 BIG-IP update for cURL
- Information disclosure in BIG-IP Next SPK/CNF libcurl
- Information disclosure in BIG-IQ Centralized Management libcurl
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Anolis OS update for curl
- Anolis OS update for curl
- PowerProtect Data Protection software update for third-party components
- Dell EMC NetWorker vProxy update for third-party components
- Multiple vulnerabilities in IBM webMethods Managed File Transfer
- Meinberg LANTIME firmware update for third-party components (January 2024)
- Multiple vulnerabilities in Dell Data Protection Search
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 7.0