CVE-2022-27776
Published on: Not Yet Published
Last Modified on: 01/05/2023 06:06:00 PM UTC
Certain versions of Fabric Operating System from Brocade contain the following vulnerability:
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
- CVE-2022-27776 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 4.3 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
[SECURITY] Fedora 37 Update: mediawiki-1.38.2-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
HackerOne | hackerone.com text/html |
![]() |
curl: Multiple Vulnerabilities (GLSA 202212-01) — Gentoo security | security.gentoo.org text/html |
![]() |
Debian -- Security Information -- DSA-5197-1 curl | www.debian.org Depreciated Link text/html |
![]() |
[SECURITY] [DLA 3085-1] curl security update | lists.debian.org text/html |
![]() |
May 2022 Libcurl Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
[SECURITY] Fedora 36 Update: mediawiki-1.37.4-1.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
Related QID Numbers
- 159919 Oracle Enterprise Linux Security Update for curl (ELSA-2022-5313)
- 159933 Oracle Enterprise Linux Security Update for curl (ELSA-2022-5245)
- 180909 Debian Security Update for curl (DSA 5197-1)
- 180969 Debian Security Update for curl (DLA 3085-1)
- 198759 Ubuntu Security Notification for curl Vulnerabilities (USN-5397-1)
- 240502 Red Hat Update for curl (RHSA-2022:5245)
- 240504 Red Hat Update for curl (RHSA-2022:5313)
- 282695 Fedora Security Update for curl (FEDORA-2022-3d8f00cde2)
- 282723 Fedora Security Update for curl (FEDORA-2022-3517572083)
- 282754 Fedora Security Update for curl (FEDORA-2022-8277bef335)
- 283101 Fedora Security Update for mediawiki (FEDORA-2022-f83aec6d57)
- 296082 Oracle Solaris 11.4 Support Repository Update (SRU) 48.126.1 Missing (CPUJUL2022)
- 353292 Amazon Linux Security Advisory for curl : ALAS2-2022-1792
- 354255 Amazon Linux Security Advisory for curl : ALAS-2022-1646
- 354277 Amazon Linux Security Advisory for curl : ALAS2022-2022-055
- 354292 Amazon Linux Security Advisory for curl : ALAS2022-2022-206
- 354341 Amazon Linux Security Advisory for curl : ALAS2022-2022-065
- 354587 Amazon Linux Security Advisory for curl : ALAS-2022-206
- 355207 Amazon Linux Security Advisory for curl : ALAS2023-2023-083
- 377351 Alibaba Cloud Linux Security Update for curl (ALINUX3-SA-2022:0142)
- 500138 Alpine Linux Security Update for curl
- 501954 Alpine Linux Security Update for curl
- 502212 Alpine Linux Security Update for curl
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 671910 EulerOS Security Update for curl (EulerOS-SA-2022-1961)
- 671934 EulerOS Security Update for curl (EulerOS-SA-2022-1991)
- 671963 EulerOS Security Update for curl (EulerOS-SA-2022-2153)
- 671972 EulerOS Security Update for curl (EulerOS-SA-2022-2128)
- 672198 EulerOS Security Update for curl (EulerOS-SA-2022-2454)
- 690855 Free Berkeley Software Distribution (FreeBSD) Security Update for curl (92a4d881-c6cf-11ec-a06f-d4c9ef517024)
- 690889 Free Berkeley Software Distribution (FreeBSD) Security Update for mediawiki (5ab54ea0-fa94-11ec-996c-080027b24e86)
- 710693 Gentoo Linux curl Multiple Vulnerabilities (GLSA 202212-01)
- 752123 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2022:1657-1)
- 752137 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2022:1680-1)
- 902166 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (9893)
- 902178 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (9893-1)
- 91922 Microsoft Windows Security Update for July 2022
- 91927 Microsoft Azure Stack Hub Security Updates for July 2022
- 940598 AlmaLinux Security Update for curl (ALSA-2022:5313)
- 960152 Rocky Linux Security Update for curl (RLSA-2022:5313)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Brocade | Fabric Operating System | - | All | All | All |
Operating System | Debian | Debian Linux | 10.0 | All | All | All |
Operating System | Debian | Debian Linux | 11.0 | All | All | All |
Operating System | Fedoraproject | Fedora | 36 | All | All | All |
Operating System | Fedoraproject | Fedora | 37 | All | All | All |
Application | Haxx | Curl | All | All | All | All |
Application | Netapp | Clustered Data Ontap | - | All | All | All |
Hardware
| Netapp | H300s | - | All | All | All |
Operating System | Netapp | H300s Firmware | - | All | All | All |
Hardware
| Netapp | H410s | - | All | All | All |
Operating System | Netapp | H410s Firmware | - | All | All | All |
Hardware
| Netapp | H500s | - | All | All | All |
Operating System | Netapp | H500s Firmware | - | All | All | All |
Hardware
| Netapp | H700s | - | All | All | All |
Operating System | Netapp | H700s Firmware | - | All | All | All |
Operating System | Netapp | Hci Bootstrap Os | - | All | All | All |
Hardware
| Netapp | Hci Compute Node | - | All | All | All |
Application | Netapp | Solidfire Hci Management Node | - | All | All | All |
Application | Netapp | Solidfire Hci Storage Node | - | All | All | All |
- cpe:2.3:o:brocade:fabric_operating_system:-:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*:
- cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:hci_bootstrap_os:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-27776 Auth/cookie leak on redirect is curl not clearing custom auth + cookie headers when following redire… twitter.com/i/web/status/1… | 2022-04-27 06:36:03 |
![]() |
HackerOne Bug Bounty Disclosure: cve-2022-27776:-auth/cookie-leak-on-redirectbynyymi - redpacketsecurity.com/hackerone-bugb… | 2022-04-27 17:02:13 |
![]() |
CVE-2022-27774 and CVE-2022-27776 existed in curl release code for **8603** days. A new record age for sec vuln in… twitter.com/i/web/status/1… | 2022-04-28 06:28:54 |
![]() |
The vuln CVE-2022-27776 has a tweet created 0 days ago and retweeted 15 times. twitter.com/bagder/status/… #pow1rtrtwwcve | 2022-04-28 10:06:01 |
![]() |
cURL security update-CVE-2022-27776 - redpacketsecurity.com/curl-security-… | 2022-05-05 10:02:27 |
![]() |
cve.report/CVE-2022-27776 A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak au… twitter.com/i/web/status/1… | 2022-06-02 16:35:11 |
![]() |
Seems Like OPNsense 22.1.6 Really Needs an Update Soon... | 2022-05-05 18:58:28 |
![]() |
DSM Version: 7.2-64561 | 2023-05-22 03:16:44 |