Количество 14
Количество 14
GHSA-59mm-6rr4-j9p2
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

CVE-2023-46218
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

CVE-2023-46218
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

CVE-2023-46218
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

CVE-2023-46218
CVE-2023-46218
This flaw allows a malicious HTTP server to set "super cookies" in cur ...

ROS-20240328-11
Уязвимость curl
ELSA-2024-1129
ELSA-2024-1129: curl security update (MODERATE)

BDU:2024-02420
Уязвимость утилиты командной строки cURL, связанная с отсутствием защиты служебных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

SUSE-SU-2023:4659-1
Security update for curl

SUSE-SU-2023:4653-1
Security update for curl

SUSE-SU-2023:4650-1
Security update for curl

RLSA-2024:1601
Moderate: curl security and bug fix update
ELSA-2024-1601
ELSA-2024-1601: curl security and bug fix update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-59mm-6rr4-j9p2 This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
![]() | CVE-2023-46218 This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
![]() | CVE-2023-46218 This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад |
![]() | CVE-2023-46218 This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
![]() | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2023-46218 This flaw allows a malicious HTTP server to set "super cookies" in cur ... | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
![]() | ROS-20240328-11 Уязвимость curl | CVSS3: 6.5 | 0% Низкий | около 1 года назад |
ELSA-2024-1129 ELSA-2024-1129: curl security update (MODERATE) | больше 1 года назад | |||
![]() | BDU:2024-02420 Уязвимость утилиты командной строки cURL, связанная с отсутствием защиты служебных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации | CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
![]() | SUSE-SU-2023:4659-1 Security update for curl | больше 1 года назад | ||
![]() | SUSE-SU-2023:4653-1 Security update for curl | больше 1 года назад | ||
![]() | SUSE-SU-2023:4650-1 Security update for curl | больше 1 года назад | ||
![]() | RLSA-2024:1601 Moderate: curl security and bug fix update | около 1 года назад | ||
ELSA-2024-1601 ELSA-2024-1601: curl security and bug fix update (MODERATE) | около 1 года назад |
Уязвимостей на страницу