Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p8vh-85vc-66x9

Опубликовано: 03 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and not using thetrailing dot in the URL.

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and not using thetrailing dot in the URL.

EPSS

Процентиль: 30%
0.0011
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-319
CWE-325

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 3 лет назад

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.

CVSS3: 5.3
redhat
около 3 лет назад

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.

CVSS3: 4.3
nvd
около 3 лет назад

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.

CVSS3: 4.3
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 4.3
debian
около 3 лет назад

Using its HSTS support, curl can be instructed to use HTTPS directly i ...

EPSS

Процентиль: 30%
0.0011
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-319
CWE-325