CVE-2023-46219Missing Encryption of Sensitive Data in Curl

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 57.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12

Description

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDhaxx/curl7.84.08.5.0
Alpinehaxx/curl< 8.5.0-r0+8
Debianhaxx/curl< 7.88.1-10+deb12u5+2
CVEListV5curl/curl8.4.08.4.0

Also affects: Fedora 38

🔴Vulnerability Details

5
OSV
CVE-2023-46219: When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of2023-12-12
OSV
CVE-2023-46219: When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of2023-12-12
CVEList
CVE-2023-46219: When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of2023-12-12
GHSA
GHSA-fj44-3xpp-9cx2: When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of2023-12-12
OSV
curl vulnerabilities2023-12-06

📋Vendor Advisories

4
Microsoft
When saving HSTS data to an excessively long file name curl could end up removing all contents making subsequent requests using that file unaware of the HSTS status they should otherwise use.2023-12-12
Red Hat
curl: excessively long file name may lead to unknown HSTS status2023-12-06
Ubuntu
curl vulnerabilities2023-12-06
Debian
CVE-2023-46219: curl - When saving HSTS data to an excessively long file name, curl could end up removi...2023

💬Community

1
HackerOne
CVE-2023-46219: HSTS long file name clears contents2023-12-08
CVE-2023-46219 — Missing Encryption of Sensitive Data | cvebase