3.7

CVE-2022-35252

Exploit
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haxx ≫ Curl Version < 7.85.0
Netapp ≫ Element Software Version -
Netapp ≫ Hci Management Node Version -
Netapp ≫ Solidfire Version -
Netapp ≫ Bootstrap Os Version -
   Netapp ≫ Hci Compute Node Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Apple ≫ macOS Version >= 11.0 < 11.7.3
Apple ≫ macOS Version >= 12.0.0 < 12.6.3
Debian ≫ Debian Linux Version 10.0
Splunk ≫ Universal Forwarder Version >= 8.2.0 < 8.2.12
Splunk ≫ Universal Forwarder Version >= 9.0.0 < 9.0.6
Splunk ≫ Universal Forwarder Version 9.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.91% 0.776
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA-ADP 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://security.gentoo.org/glsa/202212-01
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2023/Jan/20
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2023/Jan/21
Third Party Advisory
Mailing List
https://hackerone.com/reports/1613943
Third Party Advisory
Exploit
Issue Tracking
https://security.netapp.com/advisory/ntap-20220930-0005/
Third Party Advisory
https://support.apple.com/kb/HT213603
Third Party Advisory
https://support.apple.com/kb/HT213604
Third Party Advisory