CVE-2022-22576: High severity haxx curl vulnerability
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S) IMAP(S) POP3(S) and LDAP(S) (openldap only).
Other sources
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22576?
CVE-2022-22576 is an improper authentication vulnerability in curl, versions 7.33.0 to 7.82.0, which allows reuse of OAuth2-authenticated connections without proper authentication.
How does CVE-2022-22576 affect SASL-enabled protocols?
CVE-2022-22576 affects SASL-enabled protocols by allowing reuse of OAuth2-authenticated connections without proper authentication.
Which software versions are affected by CVE-2022-22576?
Versions 7.33.0 to 7.82.0 of curl are affected by CVE-2022-22576, as well as certain versions of Debian Linux, NetApp Clustered Data ONTAP, NetApp Solidfire, Brocade Fabric Operating System, and NetApp Bootstrap OS.
What is the severity of CVE-2022-22576?
CVE-2022-22576 has a severity rating of 8.1 (high).
How can I fix CVE-2022-22576?
To fix CVE-2022-22576, update curl to version 7.83.0 or later.