CVE-2021-22923

Description

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the users expectations and intentions and without telling the user it happened.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.122

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2021-22922,CVE-2021-22923,CVE-2021-22925,CVE-2021-22926 are affected in Curl For Windows 7.77.0Windows
Vulnerabilities CVE-2021-22926,CVE-2021-22925,CVE-2021-22924,CVE-2021-22923,CVE-2021-22922 are fixed in Curl For Windows 7.78.0Windows
SUSE-SU-2021:2462-1(SUSE Linux Enterprise Server 12-SP5 ) curl-7.60.0-11.23.1.x86_64.rpmLinux
SUSE-SU-2021:2462-1(SUSE Linux Enterprise Server 12-SP5 ) curl-debuginfo-7.60.0-11.23.1.x86_64.rpmLinux
SUSE-SU-2021:2462-1(SUSE Linux Enterprise Server 12-SP5 ) curl-debugsource-7.60.0-11.23.1.x86_64.rpmLinux
SUSE-SU-2021:2462-1(SUSE Linux Enterprise Server 12-SP5 ) libcurl4-7.60.0-11.23.1.x86_64.rpmLinux
SUSE-SU-2021:2462-1(SUSE Linux Enterprise Server 12-SP5 ) libcurl4-32bit-7.60.0-11.23.1.x86_64.rpmLinux
SUSE-SU-2021:2462-1(SUSE Linux Enterprise Server 12-SP5 ) libcurl4-debuginfo-7.60.0-11.23.1.x86_64.rpmLinux
SUSE-SU-2021:2462-1(SUSE Linux Enterprise Server 12-SP5 ) libcurl4-debuginfo-32bit-7.60.0-11.23.1.x86_64.rpmLinux
(RHSA-2021:3582) curl security update curl-7.61.1-18.el8_4.1.x86_64.rpmLinux
(RHSA-2021:3582) curl security update curl-debugsource-7.61.1-18.el8_4.1.i686.rpmLinux
(RHSA-2021:3582) curl security update curl-debugsource-7.61.1-18.el8_4.1.x86_64.rpmLinux
(RHSA-2021:3582) curl security update libcurl-7.61.1-18.el8_4.1.i686.rpmLinux
(RHSA-2021:3582) curl security update libcurl-7.61.1-18.el8_4.1.x86_64.rpmLinux
(RHSA-2021:3582) curl security update libcurl-devel-7.61.1-18.el8_4.1.i686.rpmLinux
(RHSA-2021:3582) curl security update libcurl-devel-7.61.1-18.el8_4.1.x86_64.rpmLinux
(RHSA-2021:3582) curl security update libcurl-minimal-7.61.1-18.el8_4.1.i686.rpmLinux
(RHSA-2021:3582) curl security update libcurl-minimal-7.61.1-18.el8_4.1.x86_64.rpmLinux
Curl update (ELSA-2021-3582) curl-7.61.1-18.el8_4.1.x86_64.rpmLinux
Libcurl update (ELSA-2021-3582) libcurl-7.61.1-18.el8_4.1.i686.rpmLinux
Libcurl update (ELSA-2021-3582) libcurl-7.61.1-18.el8_4.1.x86_64.rpmLinux
Libcurl-devel update (ELSA-2021-3582) libcurl-devel-7.61.1-18.el8_4.1.i686.rpmLinux
Libcurl-devel update (ELSA-2021-3582) libcurl-devel-7.61.1-18.el8_4.1.x86_64.rpmLinux
Libcurl-minimal update (ELSA-2021-3582) libcurl-minimal-7.61.1-18.el8_4.1.i686.rpmLinux
Libcurl-minimal update (ELSA-2021-3582) libcurl-minimal-7.61.1-18.el8_4.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234