9.8

CVE-2022-32221

Exploit
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haxx ≫ Curl Version < 7.86.0
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Apple ≫ macOS Version < 12.6.3
Splunk ≫ Universal Forwarder Version >= 8.2.0 < 8.2.12
Splunk ≫ Universal Forwarder Version >= 9.0.0 < 9.0.6
Splunk ≫ Universal Forwarder Version 9.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.33% 0.899
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

https://security.gentoo.org/glsa/202212-01
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2023/Jan/20
Third Party Advisory
Mailing List
https://support.apple.com/kb/HT213604
Third Party Advisory
http://seclists.org/fulldisclosure/2023/Jan/19
Third Party Advisory
Mailing List
https://support.apple.com/kb/HT213605
Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/05/17/4
Mailing List
https://hackerone.com/reports/1704017
Third Party Advisory
Exploit
Issue Tracking
https://security.netapp.com/advisory/ntap-20230110-0006/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20230208-0002/
Third Party Advisory
https://www.debian.org/security/2023/dsa-5330
Third Party Advisory