CVE-2023-23914
Summary
| CVE | CVE-2023-23914 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-23 20:15:00 UTC |
| Updated | 2024-03-27 14:55:00 UTC |
| Description | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| HackerOne |
MISC |
hackerone.com |
|
| curl: Multiple Vulnerabilities (GLSA 202310-12) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| February 2023 cURL/libcURL Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183053 Debian Security Update for curl (CVE-2023-23914)
- 199191 Ubuntu Security Notification for curl Vulnerabilities (USN-5891-1)
- 241574 Red Hat Update for JBoss Core Services (RHSA-2023:3354)
- 283721 Fedora Security Update for curl (FEDORA-2023-ddf6575695)
- 354789 Amazon Linux Security Advisory for curl : ALAS2-2023-1986
- 355123 Amazon Linux Security Advisory for curl : ALAS2023-2023-114
- 378453 NetApp Clustered Data Open Network Technology for Appliance Products (ONTAP) Denial of Service (DoS) Vulnerability (NTAP-20230309-0006)
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378677 Oracle Hypertext Transfer Protocol Server (HTTP Server) Server Multiple Vulnerabilities (CPUJUL2023)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 44183 Juniper Network Operating System (Junos OS) Multiple Security Vulnerabilites (JSA79108)
- 502664 Alpine Linux Security Update for curl
- 502667 Alpine Linux Security Update for curl
- 502668 Alpine Linux Security Update for curl
- 502719 Alpine Linux Security Update for curl
- 503103 Alpine Linux Security Update for curl
- 505861 Alpine Linux Security Update for curl
- 673128 EulerOS Security Update for curl (EulerOS-SA-2023-2286)
- 673152 EulerOS Security Update for curl (EulerOS-SA-2023-2262)
- 691083 Free Berkeley Software Distribution (FreeBSD) Security Update for curl (be233fc6-bae7-11ed-a4fb-080027f5fec9)
- 710772 Gentoo Linux curl Multiple Vulnerabilities (GLSA 202310-12)
- 753702 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:0429-1)
- 905580 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (13633)
- 905581 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (13635)
- 905582 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (13630)
- 905584 Common Base Linux Mariner (CBL-Mariner) Security Update for cmake (13625)
- 905592 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (13659)
- 905598 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (13656)
- 905599 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (13654)
- 905602 Common Base Linux Mariner (CBL-Mariner) Security Update for cmake (13650)
- 906629 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (13654-3)
- 906710 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (13630-1)
- 906987 Common Base Linux Mariner (CBL-Mariner) Security Update for cmake (13650-1)