Описание
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
A flaw was found in libcurl. This vulnerability allows an attacker to reuse an HTTP connection set up for a given hostname using Negotiate authentication. When an initial request is made with empty credentials, a subsequent user's request can be sent over a previously authenticated connection belonging to another user. This could lead to information disclosure or unauthorized access to sensitive data.
Отчет
This Moderate flaw in libcurl allows for information disclosure when applications reuse HTTP connections with Negotiate authentication. If an initial request is made with empty credentials, a subsequent request from another user could be sent over the previously authenticated connection, potentially exposing sensitive data. This risk is specific to applications configured to use Negotiate authentication.
Меры по смягчению последствий
To mitigate this prevent connection reuse (CURLOPT_FORBID_REUSE) for transfers using Negotiate authentication with empty credentials and strictly isolate libcurl connection pools across different security principals. For defense-in-depth, enforce network boundaries to limit outbound HTTP access, mitigating the impact of any potential cross-session data exposure while pending upstream patches.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Confidential Compute Attestation | build-of-trustee/trustee-rhel9 | Affected | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Affected | ||
| Red Hat Enterprise Linux 10 | curl | Affected | ||
| Red Hat Enterprise Linux 10 | igvm | Affected | ||
| Red Hat Enterprise Linux 10 | rust | Not affected | ||
| Red Hat Enterprise Linux 10 | s390utils | Affected | ||
| Red Hat Enterprise Linux 10 | snphost | Affected | ||
| Red Hat Enterprise Linux 10 | trustee | Affected | ||
| Red Hat Enterprise Linux 6 | curl | Not affected | ||
| Red Hat Enterprise Linux 7 | curl | Not affected |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for ...
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
6.5 Medium
CVSS3