CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-23914

CVSS 9.1v3.1pub. 2023-02-23upd. 2025-03-12

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Haxx Curl

    APP
    Haxx
    7.77.0 – 7.88.0 (excl.)
  • Netapp Active Iq Unified Manager

    APP
    Netapp
    all versions
  • Netapp Clustered Data Ontap

    APP
    Netapp
    9.0
  • Netapp H300s

    HW
    Netapp
    all versions
  • Netapp H300s Firmware

    OS
    Netapp
    all versions
  • Netapp H410s

    HW
    Netapp
    all versions
  • Netapp H410s Firmware

    OS
    Netapp
    all versions
  • Netapp H500s

    HW
    Netapp
    all versions
  • Netapp H500s Firmware

    OS
    Netapp
    all versions
  • Netapp H700s

    HW
    Netapp
    all versions
  • Netapp H700s Firmware

    OS
    Netapp
    all versions
  • Splunk Universal Forwarder

    APP
    Splunk
    9.1.08.2.0 – 8.2.12 (excl.)9.0.0 – 9.0.6 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-54085CRITICAL10.0⚠ KEVPL ✓same product

AMI MegaRAC SPx — zdalne ominięcie uwierzytelnienia w interfejsie Redfish BMC

CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product

Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2026-10536CRITICAL9.8PL ✓same product

Use-after-free w libcurl przy operacjach HTTP/2 stream-dependency

CVE-2026-11564CRITICAL9.1PL ✓same product

libcurl: błędna weryfikacja certyfikatu przy ponownym użyciu połączenia (CWE-295)