First published: Wed Jun 01 2022(Updated: )
The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe parser and get transposed into `http://example.com/127.0.0.1/`. This flawcan be used to circumvent filters, checks and more.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
haxx curl | >=7.80.0<7.83.1 | |
netapp hci bootstrap os | ||
netapp hci compute node | ||
NetApp Clustered Data ONTAP | ||
netapp solidfire\, enterprise sds \& hci storage node | ||
netapp solidfire \& hci management node | ||
netapp h410s firmware | ||
netapp h410s | ||
netapp h700s firmware | ||
netapp h700s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h300s firmware | ||
netapp h300s | ||
All of | ||
netapp hci bootstrap os | ||
netapp hci compute node | ||
All of | ||
netapp h410s firmware | ||
netapp h410s | ||
All of | ||
netapp h700s firmware | ||
netapp h700s | ||
All of | ||
NetApp H500S Firmware | ||
netapp h500s | ||
All of | ||
netapp h300s firmware | ||
netapp h300s | ||
Splunk Universal Forwarder | >=8.2.0<8.2.12 | |
Splunk Universal Forwarder | >=9.0.0<9.0.6 | |
Splunk Universal Forwarder | =9.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.