Логотип exploitDog
bind:CVE-2023-23914
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-23914

Количество 9

Количество 9

ubuntu логотип

CVE-2023-23914

больше 2 лет назад

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2023-23914

больше 2 лет назад

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23914

больше 2 лет назад

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2023-23914

больше 2 лет назад

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2023-23914

больше 2 лет назад

A cleartext transmission of sensitive information vulnerability exists ...

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20230417-05

около 2 лет назад

Уязвимость curl

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-75qm-2q4j-qx6g

больше 2 лет назад

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

EPSS: Низкий
fstec логотип

BDU:2023-02154

больше 2 лет назад

Уязвимость механизма HSTS (HTTP Strict Transport Security) утилиты командной строки cURL, позволяющая нарушителю изменить функциональность HSTS при последовательном запросе нескольких URL-адресов

CVSS3: 9.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0429-1

больше 2 лет назад

Security update for curl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-23914

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-23914

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23914

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 9.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23914

A cleartext transmission of sensitive information vulnerability exists ...

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
redos логотип
ROS-20230417-05

Уязвимость curl

CVSS3: 9.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-75qm-2q4j-qx6g

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-02154

Уязвимость механизма HSTS (HTTP Strict Transport Security) утилиты командной строки cURL, позволяющая нарушителю изменить функциональность HSTS при последовательном запросе нескольких URL-адресов

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0429-1

Security update for curl

больше 2 лет назад

Уязвимостей на страницу