cbcvebase.
CVE-2023-46219
published 2023-12-12

CVE-2023-46219: When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS…

PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.13%
62.3th percentile
When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
curlcurl8.4.0 – 8.4.0
debiancurl< curl 7.88.1-10+deb12u5 (bookworm)curl 7.88.1-10+deb12u5 (bookworm)
fedoraprojectfedora
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 8.5.0-r08.5.0-r0
haxxcurl>= 0 < 7.88.1-10+deb12u57.88.1-10+deb12u5
haxxcurl>= 0 < 8.5.0-18.5.0-1
haxxcurl>= 0 < 8.5.0-18.5.0-1
haxxcurl>= 0 < 7.68.0-1ubuntu2.217.68.0-1ubuntu2.21
haxxcurl>= 0 < 7.81.0-1ubuntu1.157.81.0-1ubuntu1.15
haxxcurl>= 7.84.0 < 8.5.08.5.0
msrcazl3_cmake_3.28.2-6_on_azure_linux_3.0
msrcazl3_cmake_3.29.6-1_on_azure_linux_3.0
msrcazl3_mysql_8.0.36-1_on_azure_linux_3.0
msrcazl3_mysql_8.0.40-1_on_azure_linux_3.0
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-9_on_azure_linux_3.0

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.