First published: Wed Jun 01 2022(Updated: )
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Haxx Curl | =7.83.0 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows | ||
NetApp Clustered Data ONTAP | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
Netapp Snapcenter | ||
Netapp Solidfire \& Hci Management Node | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp Bh500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
Netapp Hci Compute Node Firmware | ||
Netapp Hci Compute Node | ||
Oracle Mysql Server | <=5.7.38 | |
Oracle Mysql Server | >=8.0.0<=8.0.29 | |
All of | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
All of | ||
Netapp Bh500s Firmware | ||
Netapp H500s | ||
All of | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
All of | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
All of | ||
Netapp Hci Compute Node Firmware | ||
Netapp Hci Compute Node | ||
Splunk Universal Forwarder | >=8.2.0<8.2.12 | |
Splunk Universal Forwarder | >=9.0.0<9.0.6 | |
Splunk Universal Forwarder | =9.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27778 is a vulnerability in Haxx Curl 7.83.0 that allows the removal of the wrong file when using the `--no-clobber` and `--remove-on-error` options.
CVE-2022-27778 has a severity rating of 8.1 (high).
CVE-2022-27778 affects Haxx Curl 7.83.0 and NetApp software including Active IQ Unified Manager, Clustered Data ONTAP, OnCommand Insight, OnCommand Workflow Automation, Snapcenter, and Solidfire & Hci Management Node.
To fix CVE-2022-27778, update Haxx Curl to version 7.83.1 or later, or apply the necessary patches for the affected NetApp software.
You can find more information about CVE-2022-27778 on the HackerOne and NetApp security advisories linked below: - [HackerOne Report](https://hackerone.com/reports/1553598) - [NetApp Advisory 1](https://security.netapp.com/advisory/ntap-20220609-0009/) - [NetApp Advisory 2](https://security.netapp.com/advisory/ntap-20220729-0004/)