First published: Wed Jun 01 2022(Updated: )
The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe parser and get transposed into `http://example.com/127.0.0.1/`. This flawcan be used to circumvent filters, checks and more.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Curl | >=7.80.0<7.83.1 | |
All of | ||
NetApp Bootstrap OS | ||
NetApp HCI Compute Node | ||
IBM Data ONTAP | ||
NetApp SolidFire Enterprise SDS | ||
NetApp SolidFire & HCI Management Node | ||
All of | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
All of | ||
NetApp H700S | ||
NetApp H700S | ||
All of | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
All of | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
Splunk Universal Forwarder | >=8.2.0<8.2.12 | |
Splunk Universal Forwarder | >=9.0.0<9.0.6 | |
Splunk Universal Forwarder | =9.1.0 | |
NetApp Bootstrap OS | ||
NetApp HCI Compute Node | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
NetApp H700S | ||
NetApp H700S | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.