CVE-2022-27782Improper Certificate Validation in Curl

Severity
7.5HIGHNVD
EPSS
0.5%
top 35.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateJan 15

Description

libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDhaxx/curl< 7.83.1
NVDsplunk/universal_forwarder8.2.08.2.12+2
Debianhaxx/curl< 7.74.0-1.3+deb11u2+3
CVEListV5https/github.com_curl_curlFixed in 7.83.1

Also affects: Debian Linux 10.0, 11.0

🔴Vulnerability Details

4
GHSA
GHSA-x38v-8q6p-w65c: libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse2022-06-03
OSV
CVE-2022-27782: libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse2022-06-02
CVEList
CVE-2022-27782: libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse2022-06-01
OSV
curl vulnerabilities2022-05-11

📋Vendor Advisories

6
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (cURL) — CVE-2022-277822023-01-15
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (cURL) — CVE-2022-277822022-10-15
Microsoft
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection po2022-06-14
Ubuntu
curl vulnerabilities2022-05-11
Red Hat
curl: TLS and SSH connection too eager reuse2022-05-11

💬Community

2
HackerOne
CVE-2022-27782: TLS and SSH connection too eager reuse2022-05-12
HackerOne
CVE-2022-27782: TLS and SSH connection too eager reuse2022-05-11
CVE-2022-27782 — Improper Certificate Validation | cvebase