Information disclosure in cURL - CVE-2023-46218
Published: December 6, 2023
cURL
Integrated Data protection Appliance (IDPA)
IBM Qradar SIEM
Data Protection Search
Amazon Linux AMI
Oracle Linux
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
BIG-IP Next CNF
BIG-IP Next SPK
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Red Hat OpenShift Builds
Data Lakehouse
Migration Toolkit for Runtimes
Service Interconnect
Service Telemetry Framework
Oracle Communications Converged Charging System
Cryostat
IBM MQ Operator
OpenShift Logging
Red Hat Migration Toolkit for Applications
Oracle Communications Diameter Signaling Router
Oracle HTTP Server
IBM Cloud Transformation Advisor
IBM Cloud Object Storage Systems
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
EasyApache
App Connect Enterprise Certified Container
IBM Security Verify Governance
IBM QRadar WinCollect Agent
Red Hat OpenStack
EMC NetWorker Server
Juniper Cloud Native Router
Telemetry Dashboard
Dell EMC PowerProtect Data Protection
Liquidware
SmartFabric OS10
webMethods Managed File Transfer
Citrix Workspace App
Webex App VDI
Storage Copy Data Management
Cloud Pak for Network Automation
Enterprise SONiC
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Total Storage Service Console (TSSC) / TS4500 IMC
Storage Protect Plus Server
NetWorker Management Console (NMC)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Nessus Network Monitor
VMware Horizon Client
Red Hat OpenShift GitOps
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Supplied MQ Advanced Queue Manager Container images
LANTIME Operating System Firmware (LTOS)
BIG-IP
PowerScale OneFS
Junos cRPD
Juniper Secure Analytics (JSA)
Dell EMC NetWorker vProxy
Red Hat Single Sign-On
BIG-IQ Centralized Management
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
curl (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl3 (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libcurl4-debuginfo
libcurl4-32bit-debuginfo
libcurl-devel
curl
curl-debuginfo
libcurl4
libcurl4-32bit
curl-debugsource
curl (Red Hat package)
libcurl-minimal
curl-minimal
curl-doc
libcurl
curl-help
curl (Debian package)
libcurl4-debuginfo-32bit
libcurl-devel-64bit
libcurl4-64bit-debuginfo
libcurl4-64bit
libcurl-devel-32bit
jbcs-httpd24-curl (Red Hat package)
net-misc/curl
Cisco Jabber
BIG-IP Next Central Manager
Cisco Webex Meetings
JBoss Core Services
AMQ Broker
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an error in curl that allows a malicious HTTP server to set "super cookies" that are then passed back to more origins than what is otherwise allowed or possible. A remote attacker can force curl to send such cookie to different and unrelated sites and domains.