cbcvebase.
CVE-2023-23914
published 2023-02-23

CVE-2023-23914: A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are…

critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiancurl< curl 7.88.1-1 (bookworm)curl 7.88.1-1 (bookworm)
haxxcurl>= 0 < 7.88.1-17.88.1-1
haxxcurl>= 0 < 7.88.1-17.88.1-1
haxxcurl>= 0 < 7.88.1-17.88.1-1
haxxcurl>= 0 < 7.58.0-2ubuntu3.237.58.0-2ubuntu3.23
haxxcurl>= 0 < 7.68.0-1ubuntu2.167.68.0-1ubuntu2.16
haxxcurl>= 0 < 7.81.0-1ubuntu1.87.81.0-1ubuntu1.8
haxxcurl>= 7.77.0 < 7.88.07.88.0
httpsgithub.com_curl_curl
msrcazl3_cmake_3.21.4-10_on_azure_linux_3.0
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.11.1-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_cmake_3.21.4-6_on_cbl_mariner_2.0
msrccbl2_curl_7.88.1-1_on_cbl_mariner_2.0
msrccbl2_mysql_8.0.32-1_on_cbl_mariner_2.0
msrccbl2_rust_1.68.2-5_on_cbl_mariner_2.0
msrccbl2_tensorflow_2.11.1-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL