Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2023-23914

Published: 15 February 2023

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

Notes

AuthorNote
mdeslaur
introduced in 7.77

Priority

Low

Cvss 3 Severity Score

9.1

Score breakdown

Status

Package Release Status
curl
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(code not present)
focal Not vulnerable
(code not present)
jammy
Released (7.81.0-1ubuntu1.8)
kinetic
Released (7.85.0-1ubuntu0.3)
lunar
Released (7.87.0-2ubuntu1)
trusty Not vulnerable
(code not present)
upstream
Released (7.88.0)
xenial Not vulnerable
(code not present)
Patches:
upstream: https://github.com/curl/curl/commit/076a2f629119222aeeb50f5a03bf9f9052fabb9a
upstream: https://github.com/curl/curl/commit/0bf8b796a0ea98395b390c7807187982215f5c11
upstream: https://github.com/curl/curl/commit/ca02a77f05bd5cef20618c8f741aa48b7be0a648
upstream: https://github.com/curl/curl/commit/dc0725244a3163f1e2d5f51165db3a1a430f3ba0
upstream: https://github.com/curl/curl/commit/ea5aaaa5ede53819f8bc7ae767fc2d13d3704d37

Severity score breakdown

Parameter Value
Base score 9.1
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N