cbcvebase.
CVE-2021-22923
published 2021-08-05

CVE-2021-22923: When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same…

PriorityP430medium5.3CVSS 3.1
AVNACHPRNUIRSUCHINAN
EPSS
1.84%
76.3th percentile
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiancurl< curl 7.79.1-1 (bookworm)curl 7.79.1-1 (bookworm)
fedoraprojectfedora
haxxcurl>= 0 < 7.79.1-17.79.1-1
haxxcurl>= 0 < 7.79.1-17.79.1-1
haxxcurl>= 0 < 7.79.1-17.79.1-1
haxxcurl>= 7.27.0 < 7.78.07.78.0
httpsgithub.com_curl_curl
msrccbl2_curl_7.76.0-5_on_cbl_mariner_2.0
msrccm1_curl_7.76.0-5_on_cbl_mariner_1.0
oraclemysql_server5.7.0 – 5.7.35
oraclemysql_server8.0.0 – 8.0.26
siemenssinec_infrastructure_network_services< 1.0.1.11.0.1.1
splunkuniversal_forwarder
splunkuniversal_forwarder>= 8.2.0 < 8.2.128.2.12
splunkuniversal_forwarder>= 9.0.0 < 9.0.69.0.6

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.