First published: Thu Apr 28 2022(Updated: )
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/curl | <=7.64.0-4+deb10u2 | 7.64.0-4+deb10u7 7.74.0-1.3+deb11u9 7.74.0-1.3+deb11u10 7.88.1-10+deb12u3 7.88.1-10+deb12u4 8.4.0-2 |
debian/curl | <=7.82.0-2<=7.74.0-1.3+deb11u1<=7.64.0-4+deb10u2 | |
Haxx Curl | >=7.33.0<7.83.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
NetApp Clustered Data ONTAP | ||
Netapp Solidfire \& Hci Management Node | ||
Netapp Solidfire \& Hci Storage Node | ||
Brocade Fabric Operating System | ||
All of | ||
Netapp Bootstrap Os | ||
Netapp Hci Compute Node | ||
All of | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
All of | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
All of | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
All of | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
Splunk Universal Forwarder | >=8.2.0<8.2.12 | |
Splunk Universal Forwarder | >=9.0.0<9.0.6 | |
Splunk Universal Forwarder | =9.1.0 | |
Netapp Bootstrap Os | ||
Netapp Hci Compute Node | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H410s Firmware | ||
Netapp H410s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22576 is an improper authentication vulnerability in curl, versions 7.33.0 to 7.82.0, which allows reuse of OAuth2-authenticated connections without proper authentication.
CVE-2022-22576 affects SASL-enabled protocols by allowing reuse of OAuth2-authenticated connections without proper authentication.
Versions 7.33.0 to 7.82.0 of curl are affected by CVE-2022-22576, as well as certain versions of Debian Linux, NetApp Clustered Data ONTAP, NetApp Solidfire, Brocade Fabric Operating System, and NetApp Bootstrap OS.
CVE-2022-22576 has a severity rating of 8.1 (high).
To fix CVE-2022-22576, update curl to version 7.83.0 or later.