CVE-2021-22897: Medium severity haxx curl vulnerability
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPTSSLCIPHERLIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if an application sets up multiple concurrent transfers, the last one that sets the ciphers will accidentally control the set used by all transfers. In a worst-case scenario, this weakens transport security significantly.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-22897.
What is the severity level of CVE-2021-22897?
The severity level of CVE-2021-22897 is medium.
What is the affected software for CVE-2021-22897?
The affected software for CVE-2021-22897 includes Haxx Curl, Oracle Communications Cloud Native Core Binding Support Function, Oracle Communications Cloud Native Core Network Function Cloud Native Environment, Oracle Communications Cloud Native Core Network Repository Function, Oracle Communications Cloud Native Core Network Slice Selection Function, Oracle Communications Cloud Native Core Service Communication Proxy, Oracle Essbase, Oracle MySQL Server, Netapp Cloud Backup, Netapp Solidfire, Enterprise Sds & Hci Storage Node, Netapp Solidfire & Hci Management Node, Netapp Solidfire Baseboard Management Controller Firmware, Netapp HCI Compute Node Firmware, Netapp H300e Firmware, Netapp H300s Firmware, Netapp H410s Firmware, Netapp H500e Firmware, Netapp H500s Firmware, Netapp H700e Firmware, Netapp H700s Firmware, and Siemens Sinec Infrastructure Network Services.
How is the data element exposed to the wrong session in CVE-2021-22897?
The data element is exposed to the wrong session in CVE-2021-22897 due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library.
Where can I find more information about CVE-2021-22897?
You can find more information about CVE-2021-22897 in the references provided: [SSA-389290.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf), [CVE-2021-22897](https://curl.se/docs/CVE-2021-22897.html), [GitHub commit](https://github.com/curl/curl/commit/bbb71507b7bab52002f9b1e0880bed6a32834511).