Описание
Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same easy handle but without the custom Host: header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 8.20.0-2ubuntu1 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra-legacy/xenial | not-affected | code not present |
| esm-infra/bionic | not-affected | code not present |
| esm-infra/focal | not-affected | code not present |
| esm-infra/xenial | not-affected | code not present |
| jammy | released | 7.81.0-1ubuntu1.24 |
| noble | released | 8.5.0-2ubuntu10.9 |
| questing | released | 8.14.1-2ubuntu1.3 |
| resolute | released | 8.18.0-1ubuntu2.1 |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
Using libcurl, when a custom `Host:` header is first set for an HTTP r ...
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
EPSS
7.5 High
CVSS3