Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

ubuntu логотип

CVE-2023-23915

больше 3 лет назад

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2023-23915

больше 3 лет назад

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2023-23915

больше 3 лет назад

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-23915

больше 3 лет назад

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23915

больше 3 лет назад

A cleartext transmission of sensitive information vulnerability exists ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2c3h-vr56-625m

больше 3 лет назад

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-11571

больше 3 лет назад

Уязвимость утилиты командной строки cURL, связанная c передачей конфиденциальной информации открытым текстом, позволяющая нарушителю выполнить атаку MitM

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0429-1

больше 3 лет назад

Security update for curl

EPSS: Низкий
redos логотип

ROS-20250923-42

10 месяцев назад

Множественные уязвимости libcurl

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20250923-22

10 месяцев назад

Множественные уязвимости curl

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-23915

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-23915

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 4.2
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-23915

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2023-23915

A cleartext transmission of sensitive information vulnerability exists ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2c3h-vr56-625m

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2025-11571

Уязвимость утилиты командной строки cURL, связанная c передачей конфиденциальной информации открытым текстом, позволяющая нарушителю выполнить атаку MitM

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0429-1

Security update for curl

больше 3 лет назад
redos логотип
ROS-20250923-42

Множественные уязвимости libcurl

CVSS3: 6.5
10 месяцев назад
redos логотип
ROS-20250923-22

Множественные уязвимости curl

CVSS3: 6.5
10 месяцев назад

Уязвимостей на страницу