7.5

CVE-2022-27782

Exploit
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haxx ≫ Curl Version < 7.83.1
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Splunk ≫ Universal Forwarder Version >= 8.2.0 < 8.2.12
Splunk ≫ Universal Forwarder Version >= 9.0.0 < 9.0.6
Splunk ≫ Universal Forwarder Version 9.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.93% 0.859
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2022/dsa-5197
Third Party Advisory
Mailing List
https://security.gentoo.org/glsa/202212-01
Third Party Advisory
https://security.netapp.com/advisory/ntap-20220609-0009/
Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/03/20/6
Mailing List
https://hackerone.com/reports/1555796
Third Party Advisory
Exploit