Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-22576

Опубликовано: 27 апр. 2022
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

A vulnerability was found in curl. This security flaw allows reusing OAUTH2-authenticated connections without properly ensuring that the connection was authenticated with the same credentials set for this transfer. This issue leads to an authentication bypass, either by mistake or by a malicious actor.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 3.1 on Red Hat Enterprise Linuxrh-dotnet31-curlOut of support scope
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected
Red Hat JBoss Core ServicescurlNot affected
Red Hat Software Collectionshttpd24-curlWill not fix
Red Hat Enterprise Linux 8curlFixedRHSA-2022:531330.06.2022
Red Hat Enterprise Linux 9curlFixedRHSA-2022:524501.07.2022
Red Hat Enterprise Linux 9curlFixedRHSA-2022:524501.07.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287->CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2077541curl: OAUTH2 bearer bypass in connection re-use

EPSS

Процентиль: 53%
0.00296
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 3 лет назад

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
nvd
около 3 лет назад

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 8.1
debian
около 3 лет назад

An improper authentication vulnerability exists in curl 7.33.0 to and ...

CVSS3: 8.1
github
около 3 лет назад

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

EPSS

Процентиль: 53%
0.00296
Низкий

8.1 High

CVSS3