Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-35252

Опубликовано: 31 авг. 2022
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

A vulnerability found in curl. This security flaw happens when curl is used to retrieve and parse cookies from an HTTP(S) server, where it accepts cookies using control codes (byte values below 32), and also when cookies that contain such control codes are later sent back to an HTTP(S) server, possibly causing the server to return a 400 response. This issue effectively allows a "sister site" to deny service to siblings and cause a denial of service attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7curlOut of support scope
JBoss Core Services for RHEL 8jbcs-httpd24-curlFixedRHSA-2022:884008.12.2022
JBoss Core Services on RHEL 7jbcs-httpd24-curlFixedRHSA-2022:884008.12.2022
Red Hat Enterprise Linux 8curlFixedRHSA-2023:296316.05.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportcurlFixedRHSA-2024:042825.01.2024
Red Hat Enterprise Linux 9curlFixedRHSA-2023:247809.05.2023
Red Hat Enterprise Linux 9curlFixedRHSA-2023:247809.05.2023
Text-Only JBCScurlFixedRHSA-2022:884108.12.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2120718curl: Incorrect handling of control code characters in cookies

EPSS

Процентиль: 21%
0.00066
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
почти 3 года назад

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS3: 3.7
nvd
почти 3 года назад

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS3: 3.7
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 3.7
debian
почти 3 года назад

When curl is used to retrieve and parse cookies from a HTTP(S) server, ...

suse-cvrf
почти 3 года назад

Security update for curl

EPSS

Процентиль: 21%
0.00066
Низкий

3.1 Low

CVSS3