cbcvebase.
CVE-2023-46218
published 2023-12-07

CVE-2023-46218: This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible…

PriorityP337medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.69%
74.0th percentile
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
curlcurl8.4.0 – 8.4.0
debiancurl< curl 7.88.1-10+deb12u5 (bookworm)curl 7.88.1-10+deb12u5 (bookworm)
fedoraprojectfedora
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 7.74.0-1.3+deb11u117.74.0-1.3+deb11u11
haxxcurl>= 0 < 7.88.1-10+deb12u57.88.1-10+deb12u5
haxxcurl>= 0 < 8.5.0-18.5.0-1
haxxcurl>= 0 < 8.5.0-18.5.0-1
haxxcurl>= 0 < 7.68.0-1ubuntu2.217.68.0-1ubuntu2.21
haxxcurl>= 0 < 7.81.0-1ubuntu1.157.81.0-1ubuntu1.15
haxxcurl7.46.0 – 8.4.0
msrcazl3_cmake_3.28.2-6_on_azure_linux_3.0
msrcazl3_cmake_3.29.6-1_on_azure_linux_3.0
msrcazl3_mysql_8.0.36-1_on_azure_linux_3.0
msrcazl3_mysql_8.0.40-1_on_azure_linux_3.0
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.