Severity
6.5MEDIUM
EPSS
0.1%
top 64.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 5
Latest updateMay 24

Description

When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several of them. In a serial orparallel manner.If one of the servers hosting the contents has been breached and the contentsof the specific file on that serve

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

NVDhaxx/curl7.27.07.78.0
Debiancurl< 7.79.1-1+2
NVDoracle/mysql_server5.7.05.7.35+1
CVEListV5https://github.com/curl/curlcurl 7.27.0 to and including 7.77.0
NVDsplunk/universal_forwarder8.2.08.2.12+2

Also affects: Fedora 33

Patches

🔴Vulnerability Details

3
GHSA
GHSA-975f-fvhv-8mhx: When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file2022-05-24
CVEList
CVE-2021-22922: When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file2021-08-05
OSV
CVE-2021-22922: When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file2021-08-05

📋Vendor Advisories

3
Microsoft
When curl is instructed to download content using the metalink feature thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to ge2021-08-10
Red Hat
curl: Content not matching hash in Metalink is not being discarded2021-07-21
Debian
CVE-2021-22922: curl - When curl is instructed to download content using the metalink feature, theconte...2021

💬Community

1
HackerOne
CVE-2021-22922: Wrong content via metalink not discarded2021-07-21