First published: Wed Apr 27 2022(Updated: )
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/curl | 7.64.0-4+deb10u2 7.64.0-4+deb10u7 7.74.0-1.3+deb11u9 7.74.0-1.3+deb11u10 7.88.1-10+deb12u3 7.88.1-10+deb12u4 8.4.0-2 | |
debian/curl | <=7.74.0-1.3+deb11u1<=7.82.0-2 | |
Haxx Curl | >=7.65.0<=7.82.0 | |
Debian Debian Linux | =11.0 | |
All of | ||
Netapp Hci Bootstrap Os | ||
Netapp Hci Compute Node | ||
NetApp Clustered Data ONTAP | ||
Netapp Solidfire \& Hci Management Node | ||
Netapp Solidfire \& Hci Storage Node | ||
Brocade Fabric Operating System | ||
All of | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
All of | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
All of | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
All of | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
Splunk Universal Forwarder | >=8.2.0<8.2.12 | |
Splunk Universal Forwarder | >=9.0.0<9.0.6 | |
Splunk Universal Forwarder | =9.1.0 | |
Netapp Hci Bootstrap Os | ||
Netapp Hci Compute Node | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H410s Firmware | ||
Netapp H410s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27775 is an information disclosure vulnerability in curl version 7.65.0 to 7.82.0.
CVE-2022-27775 has a severity rating of 7.5 (High).
Versions 7.65.0 to 7.82.0 of curl are affected by CVE-2022-27775.
To fix CVE-2022-27775, update curl to version 7.88.1-10+deb12u4 or higher.
Yes, you can find more information about CVE-2022-27775 at the following references: [link1](https://security-tracker.debian.org/tracker/CVE-2022-27775), [link2](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27775), [link3](https://curl.se/docs/CVE-2022-27775.html).