CVE-2023-38546

CWE-7320 documents13 sources
Severity
3.7LOW
EPSS
0.3%
top 51.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 18
Latest updateApr 15

Description

This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates "easy handles" that are the individual handles for single transfers. libcurl provides a function call that duplicates en easy handle called [curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html). If a transfer has cookies enabled when the handle is duplicated, the cookie-enab

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 2.2 | Impact: 1.4

Affected Packages5 packages

NVDhaxx/libcurl7.9.18.4.0
CVEListV5curl/curl8.4.08.4.0
Alpinecurl< 8.4.0-r0+8
Debiancurl< 7.74.0-1.3+deb11u10+3
Ubuntucurl< 7.35.0-1ubuntu2.20+esm17+2

Patches

🔴Vulnerability Details

5
OSV
CVE-2023-38546: This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met2023-10-18
OSV
CVE-2023-38546: This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met2023-10-18
CVEList
CVE-2023-38546: This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met2023-10-18
GHSA
GHSA-x3qx-m3c2-qfhx: This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met2023-10-18
OSV
curl vulnerability2023-10-11

📋Vendor Advisories

10
Oracle
Oracle Oracle Analytics Risk Matrix: Platform Security (libcurl) — CVE-2023-385462025-04-15
Apple
CVE-2023-38546: macOS Ventura 13.6.42024-01-22
Apple
CVE-2023-38546: macOS Monterey 12.7.32024-01-22
Apple
CVE-2023-38546: macOS Sonoma 14.22023-12-11
Ubuntu
curl vulnerabilities2023-10-17

🕵️Threat Intelligence

2
Qualys
Curl 8.4.0 – Proactively Identifying Potential Vulnerable Assets2023-10-06
Qualys
Curl 8.4.0 Vulnerability Detection & Mitigation | Qualys2023-10-06

💬Community

1
HackerOne
[CVE-2023-38546] cookie injection with none file2023-11-23