Логотип exploitDog
bind: "CVE-2023-23915"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-23915"

Количество 10

Количество 10

ubuntu логотип

CVE-2023-23915

почти 3 года назад

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2023-23915

почти 3 года назад

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2023-23915

почти 3 года назад

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-23915

почти 3 года назад

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23915

почти 3 года назад

A cleartext transmission of sensitive information vulnerability exists ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2c3h-vr56-625m

почти 3 года назад

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-11571

почти 3 года назад

Уязвимость утилиты командной строки cURL, связанная c передачей конфиденциальной информации открытым текстом, позволяющая нарушителю выполнить атаку MitM

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0429-1

почти 3 года назад

Security update for curl

EPSS: Низкий
redos логотип

ROS-20250923-42

2 месяца назад

Множественные уязвимости libcurl

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20250923-22

2 месяца назад

Множественные уязвимости curl

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-23915

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-23915

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 4.2
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-23915

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 6.5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-23915

A cleartext transmission of sensitive information vulnerability exists ...

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2c3h-vr56-625m

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2025-11571

Уязвимость утилиты командной строки cURL, связанная c передачей конфиденциальной информации открытым текстом, позволяющая нарушителю выполнить атаку MitM

CVSS3: 6.5
0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:0429-1

Security update for curl

почти 3 года назад
redos логотип
ROS-20250923-42

Множественные уязвимости libcurl

CVSS3: 6.5
2 месяца назад
redos логотип
ROS-20250923-22

Множественные уязвимости curl

CVSS3: 6.5
2 месяца назад

Уязвимостей на страницу