CVE-2021-22890
Summary
| CVE | CVE-2021-22890 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-01 18:15:00 UTC |
| Updated | 2024-03-27 15:47:00 UTC |
| Description | curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server and then wrongly "short-cut" the host handshake. When confusing the tickets, a HTTPS proxy can trick libcurl to use the wrong session ticket resume for the host and thereby circumvent the server TLS certificate check and make a MITM attack to be possible to perform unnoticed. Note that such a malicious HTTPS proxy needs to provide a certificate that curl will accept for the MITMed server for an attack to work - unless curl has been told to ignore the server certificate check. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 32 Update: curl-7.69.1-8.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| curl - TLS 1.3 session ticket proxy host mixup - CVE-2021-22890 |
MISC |
curl.se |
|
| [SECURITY] Fedora 33 Update: curl-7.71.1-9.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| HackerOne |
MISC |
hackerone.com |
|
| [SECURITY] Fedora 34 Update: curl-7.76.0-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| cURL: Multiple vulnerabilities (GLSA 202105-36) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Oracle Critical Patch Update Advisory - July 2021 |
N/A |
www.oracle.com |
|
| [SECURITY] Fedora 32 Update: curl-7.69.1-8.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| [SECURITY] Fedora 34 Update: curl-7.76.0-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: curl-7.71.1-9.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| April 2021 cURL/libcURL Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 174942 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2021:1006-1)
- 178522 Debian Security Update for curl (DSA 4881-1)
- 179967 Debian Security Update for curl (CVE-2021-22890)
- 198316 Ubuntu Security Notification for Curl Vulnerabilities (USN-4898-1)
- 239451 Red Hat Update for Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP8 (RHSA-2021:2472)
- 281384 Fedora Security Update for curl (FEDORA-2021-cab5c9befb)
- 281385 Fedora Security Update for curl (FEDORA-2021-065371f385)
- 281386 Fedora Security Update for curl (FEDORA-2021-26a293c72b)
- 296059 Oracle Solaris 11.4 Support Repository Update (SRU) 36.0.1.101.2 Missing (CPUJUL2021)
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 500134 Alpine Linux Security Update for curl
- 503785 Alpine Linux Security Update for curl
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 670440 EulerOS Security Update for curl (EulerOS-SA-2021-2060)
- 670451 EulerOS Security Update for curl (EulerOS-SA-2021-2049)
- 670903 EulerOS Security Update for curl (EulerOS-SA-2021-2060)
- 690177 Free Berkeley Software Distribution (FreeBSD) Security Update for curl (d10fc771-958f-11eb-9c34-080027f515ea)
- 710078 Gentoo Linux cURL Multiple vulnerabilities (GLSA 202105-36)
- 730155 McAfee Web Gateway Multiple Vulnerabilities(WP-3580, WP-3656, WP-3815, WP-3878, WP-3882, WP-3934,WP-3935, WP-3936, WP-3999)
- 750283 OpenSUSE Security Update for curl (openSUSE-SU-2021:0510-1)
- 900279 CBL-Mariner Linux Security Update for curl 7.74.0
- 903340 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (4048)