CVE-2022-27778: High severity curl vulnerability
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when --no-clobber is used together with --remove-on-error.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-27778?
CVE-2022-27778 is a vulnerability in Haxx Curl 7.83.0 that allows the removal of the wrong file when using the `--no-clobber` and `--remove-on-error` options.
What is the severity of CVE-2022-27778?
CVE-2022-27778 has a severity rating of 8.1 (high).
Which software versions are affected by CVE-2022-27778?
CVE-2022-27778 affects Haxx Curl 7.83.0 and NetApp software including Active IQ Unified Manager, Clustered Data ONTAP, OnCommand Insight, OnCommand Workflow Automation, Snapcenter, and Solidfire & Hci Management Node.
How can I fix CVE-2022-27778?
To fix CVE-2022-27778, update Haxx Curl to version 7.83.1 or later, or apply the necessary patches for the affected NetApp software.
Where can I find more information about CVE-2022-27778?
You can find more information about CVE-2022-27778 on the HackerOne and NetApp security advisories linked below: - [HackerOne Report](https://hackerone.com/reports/1553598) - [NetApp Advisory 1](https://security.netapp.com/advisory/ntap-20220609-0009/) - [NetApp Advisory 2](https://security.netapp.com/advisory/ntap-20220729-0004/)