Логотип exploitDog
bind: "CVE-2023-46218"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-46218"

Количество 14

Количество 14

ubuntu логотип

CVE-2023-46218

больше 1 года назад

This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2023-46218

больше 1 года назад

This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-46218

больше 1 года назад

This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-46218

больше 1 года назад

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-46218

больше 1 года назад

This flaw allows a malicious HTTP server to set "super cookies" in cur ...

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20240328-11

около 1 года назад

Уязвимость curl

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-59mm-6rr4-j9p2

больше 1 года назад

This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-1129

больше 1 года назад

ELSA-2024-1129: curl security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2024-02420

больше 1 года назад

Уязвимость утилиты командной строки cURL, связанная с отсутствием защиты служебных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4659-1

больше 1 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4653-1

больше 1 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4650-1

больше 1 года назад

Security update for curl

EPSS: Низкий
rocky логотип

RLSA-2024:1601

около 1 года назад

Moderate: curl security and bug fix update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-1601

около 1 года назад

ELSA-2024-1601: curl security and bug fix update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-46218

This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-46218

This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-46218

This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 6.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-46218

This flaw allows a malicious HTTP server to set "super cookies" in cur ...

CVSS3: 6.5
0%
Низкий
больше 1 года назад
redos логотип
ROS-20240328-11

Уязвимость curl

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-59mm-6rr4-j9p2

This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2024-1129

ELSA-2024-1129: curl security update (MODERATE)

больше 1 года назад
fstec логотип
BDU:2024-02420

Уязвимость утилиты командной строки cURL, связанная с отсутствием защиты служебных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 6.5
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4659-1

Security update for curl

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4653-1

Security update for curl

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4650-1

Security update for curl

больше 1 года назад
rocky логотип
RLSA-2024:1601

Moderate: curl security and bug fix update

около 1 года назад
oracle-oval логотип
ELSA-2024-1601

ELSA-2024-1601: curl security and bug fix update (MODERATE)

около 1 года назад

Уязвимостей на страницу