CVE-2023-23915

Severity
6.5MEDIUM
EPSS
0.0%
top 86.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateFeb 27

Description

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlyco

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages5 packages

CVEListV5https://github.com/curl/curlFixed in 7.88.0
NVDhaxx/curl7.77.07.88.0
Debiancurl< 7.88.1-1+2
NVDsplunk/universal_forwarder8.2.08.2.12+2

🔴Vulnerability Details

4
OSV
curl vulnerabilities2023-02-27
OSV
CVE-2023-23915: A cleartext transmission of sensitive information vulnerability exists in curl <v72023-02-23
CVEList
CVE-2023-23915: A cleartext transmission of sensitive information vulnerability exists in curl <v72023-02-23
GHSA
GHSA-2c3h-vr56-625m: A cleartext transmission of sensitive information vulnerability exists in curl <v72023-02-23

📋Vendor Advisories

4
Ubuntu
curl vulnerabilities2023-02-27
Red Hat
curl: HSTS amnesia with --parallel2023-02-15
Microsoft
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using it2023-02-14
Debian
CVE-2023-23915: curl - A cleartext transmission of sensitive information vulnerability exists in curl <...2023

💬Community

2
HackerOne
CVE-2023-23915: HSTS amnesia with --parallel2023-02-24
HackerOne
CVE-2023-23915: HSTS amnesia with --parallel2023-02-15
CVE-2023-23915 (MEDIUM CVSS 6.5) | A cleartext transmission of sensiti | cvebase.io