First published: Tue Feb 07 2023(Updated: )
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/curl | <7.88.0 | 7.88.0 |
IBM IBM® Engineering Requirements Management DOORS | <=9.7.2.7 | |
IBM IBM® Engineering Requirements Management DOORS Web Access | <=9.7.2.7 | |
Haxx Curl | >=7.77.0<7.88.0 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
NetApp Clustered Data ONTAP | =9.0 | |
All of | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
All of | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
All of | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
All of | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
Splunk Universal Forwarder | >=8.2.0<8.2.12 | |
Splunk Universal Forwarder | >=9.0.0<9.0.6 | |
Splunk Universal Forwarder | =9.1.0 | |
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H410s Firmware | ||
Netapp H410s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-23914 is critical, with a CVSS score of 9.1.
CVE-2023-23914 affects curl versions earlier than 7.88.0, causing HSTS functionality to fail when multiple URLs are requested serially.
To fix CVE-2023-23914, update curl to version 7.88.0 or later.
You can find more information about CVE-2023-23914 at the following references: [link1](https://curl.se/docs/CVE-2023-23914.html), [link2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2170747), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2170748).
The Common Weakness Enumeration (CWE) of CVE-2023-23914 is CWE-319.