First published: Thu Apr 28 2022(Updated: )
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/curl | <=7.64.0-4+deb10u2 | 7.64.0-4+deb10u7 7.74.0-1.3+deb11u9 7.74.0-1.3+deb11u10 7.88.1-10+deb12u3 7.88.1-10+deb12u4 8.4.0-2 |
debian/curl | <=7.82.0-2<=7.74.0-1.3+deb11u1<=7.64.0-4+deb10u2 | |
Curl | >=7.33.0<7.83.0 | |
Debian | =10.0 | |
Debian | =11.0 | |
IBM Data ONTAP | ||
netapp solidfire \& hci management node | ||
netapp solidfire \& hci storage node | ||
Brocade Fabric OS | ||
All of | ||
netapp bootstrap os | ||
netapp hci compute node | ||
All of | ||
netapp h300s firmware | ||
netapp h300s | ||
All of | ||
NetApp H500S Firmware | ||
netapp h500s | ||
All of | ||
netapp h700s firmware | ||
netapp h700s | ||
All of | ||
netapp h410s firmware | ||
netapp h410s | ||
Splunk Universal Forwarder | >=8.2.0<8.2.12 | |
Splunk Universal Forwarder | >=9.0.0<9.0.6 | |
Splunk Universal Forwarder | =9.1.0 | |
netapp bootstrap os | ||
netapp hci compute node | ||
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h410s firmware | ||
netapp h410s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22576 is an improper authentication vulnerability in curl, versions 7.33.0 to 7.82.0, which allows reuse of OAuth2-authenticated connections without proper authentication.
CVE-2022-22576 affects SASL-enabled protocols by allowing reuse of OAuth2-authenticated connections without proper authentication.
Versions 7.33.0 to 7.82.0 of curl are affected by CVE-2022-22576, as well as certain versions of Debian Linux, NetApp Clustered Data ONTAP, NetApp Solidfire, Brocade Fabric Operating System, and NetApp Bootstrap OS.
CVE-2022-22576 has a severity rating of 8.1 (high).
To fix CVE-2022-22576, update curl to version 7.83.0 or later.