CVE-2022-27780

Description

The curl URL parser wrongly accepts percent-encoded URL separators like /when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like http://example.com%2F127.0.0.1/, would be allowed bythe parser and get transposed into http://example.com/127.0.0.1/. This flawcan be used to circumvent filters, checks and more.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.125

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Curl For Windows 7.83.0Windows
Multiple vulnerabilities are fixed in Curl For Windows 7.83.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.0Windows
Multiple Vulnerabilities are affected in IBM MQ 9.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.2Windows
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.81.0-1ubuntu1.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.81.0-1ubuntu1.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.58.0-2ubuntu3.19_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.58.0-2ubuntu3.19_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.68.0-1ubuntu2.12_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.68.0-1ubuntu2.12_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.74.0-1.3ubuntu2.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.74.0-1.3ubuntu2.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.81.0-1ubuntu1.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.81.0-1ubuntu1.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.58.0-2ubuntu3.19_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.58.0-2ubuntu3.19_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.68.0-1ubuntu2.12_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.68.0-1ubuntu2.12_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.74.0-1.3ubuntu2.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.74.0-1.3ubuntu2.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.81.0-1ubuntu1.6_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.81.0-1ubuntu1.6_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.58.0-2ubuntu3.21_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.58.0-2ubuntu3.21_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.68.0-1ubuntu2.14_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.68.0-1ubuntu2.14_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.74.0-1.3ubuntu2.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.74.0-1.3ubuntu2.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.81.0-1ubuntu1.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.81.0-1ubuntu1.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.58.0-2ubuntu3.19_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.58.0-2ubuntu3.19_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.68.0-1ubuntu2.12_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.68.0-1ubuntu2.12_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.74.0-1.3ubuntu2.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.74.0-1.3ubuntu2.3_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234