cbcvebase.
CVE-2022-42916
published 2022-10-29

CVE-2022-42916: In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.81%
77.3th percentile
In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replaced with ASCII counterparts as part of the IDN conversion, e.g., using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop of U+002E (.). The earliest affected version is 7.77.0 2021-05-26.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
applemacos< 12.6.312.6.3
applemacos>= 13.0 < 13.213.2
applemacos_monterey——
applemacos_ventura——
debiancurl< curl 7.86.0-1 (bookworm)curl 7.86.0-1 (bookworm)
fedoraprojectfedora——
fedoraprojectfedora——
fedoraprojectfedora——
haxxcurl>= 0 < 7.86.0-17.86.0-1
haxxcurl>= 0 < 7.86.0-17.86.0-1
haxxcurl>= 0 < 7.86.0-17.86.0-1
haxxcurl>= 0 < 7.58.0-2ubuntu3.217.58.0-2ubuntu3.21
haxxcurl>= 0 < 7.68.0-1ubuntu2.147.68.0-1ubuntu2.14
haxxcurl>= 0 < 7.81.0-1ubuntu1.67.81.0-1ubuntu1.6
haxxcurl>= 7.77.0 < 7.86.07.86.0
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0——
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0——
msrcazl3_tensorflow_2.11.1-1_on_azure_linux_3.0——
msrcazl3_tensorflow_2.16.1-1_on_azure_linux_3.0——
msrcazure_linux_3.0_arm——
msrcazure_linux_3.0_x64——
msrccbl2_curl_7.86.0-1_on_cbl_mariner_2.0——
msrccbl2_tensorflow_2.11.1-2_on_cbl_mariner_2.0——
msrccbl_mariner_1.0_arm——
msrccbl_mariner_1.0_x64——

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.