Severity
3.7LOW
EPSS
0.7%
top 26.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 5
Latest updateMay 24

Description

libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issue

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 2.2 | Impact: 1.4

Affected Packages28 packages

NVDhaxx/libcurl7.10.47.77.0
NVDoracle/mysql_server5.7.05.7.36+1
NVDsplunk/universal_forwarder8.2.08.2.12+2

Also affects: Debian Linux 10.0, 11.0, 9.0, Fedora 33

Patches

🔴Vulnerability Details

4
GHSA
GHSA-qhhj-q26m-mrw8: libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup2022-05-24
CVEList
CVE-2021-22924: libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup2021-08-05
OSV
CVE-2021-22924: libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup2021-08-05
OSV
curl vulnerabilities2021-07-22

📋Vendor Advisories

4
Microsoft
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup.Due to errors in the logic the config matching function did not take 'i2021-08-10
Ubuntu
curl vulnerabilities2021-07-22
Red Hat
curl: Bad connection reuse due to flawed path name checks2021-07-21
Debian
CVE-2021-22924: curl - libcurl keeps previously used connections in a connection pool for subsequenttra...2021

💬Community

1
HackerOne
CVE-2021-22924: Bad connection reuse due to flawed path name checks2021-07-21