The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe parser and get transposed into `http://example.com/127.0.0.1/`. This flawcan be used to circumvent filters, checks and more.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NHaxx Curl
APPHaxx7.80.0 – 7.83.1 (excl.)Netapp Clustered Data Ontap
APPNetappall versionsNetapp H300s
HWNetappall versionsNetapp H300s Firmware
OSNetappall versionsNetapp H410s
HWNetappall versionsNetapp H410s Firmware
OSNetappall versionsNetapp H500s
HWNetappall versionsNetapp H500s Firmware
OSNetappall versionsNetapp H700s
HWNetappall versionsNetapp H700s Firmware
OSNetappall versionsNetapp Hci Bootstrap Os
OSNetappall versionsNetapp Hci Compute Node
HWNetappall versionsNetapp Solidfire\, Enterprise Sds \& Hci Storage Node
APPNetappall versionsNetapp Solidfire \& Hci Management Node
APPNetappall versionsSplunk Universal Forwarder
APPSplunk9.1.08.2.0 – 8.2.12 (excl.)9.0.0 – 9.0.6 (excl.)
Related vulnerabilities
AMI MegaRAC SPx — zdalne ominięcie uwierzytelnienia w interfejsie Redfish BMC
Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
Use-after-free w libcurl przy operacjach HTTP/2 stream-dependency
libcurl: błędna weryfikacja certyfikatu przy ponownym użyciu połączenia (CWE-295)