cbcvebase.
CVE-2022-42916
published 2022-10-29

CVE-2022-42916: In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.64%
73.4th percentile
In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replaced with ASCII counterparts as part of the IDN conversion, e.g., using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop of U+002E (.). The earliest affected version is 7.77.0 2021-05-26.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
applemacos< 12.6.312.6.3
applemacos>= 13.0 < 13.213.2
applemacos_monterey
applemacos_ventura
debiancurl< curl 7.86.0-1 (bookworm)curl 7.86.0-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
haxxcurl>= 0 < 7.86.0-17.86.0-1
haxxcurl>= 0 < 7.86.0-17.86.0-1
haxxcurl>= 0 < 7.86.0-17.86.0-1
haxxcurl>= 0 < 7.58.0-2ubuntu3.217.58.0-2ubuntu3.21
haxxcurl>= 0 < 7.68.0-1ubuntu2.147.68.0-1ubuntu2.14
haxxcurl>= 0 < 7.81.0-1ubuntu1.67.81.0-1ubuntu1.6
haxxcurl>= 7.77.0 < 7.86.07.86.0
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.11.1-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_curl_7.86.0-1_on_cbl_mariner_2.0
msrccbl2_tensorflow_2.11.1-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.