CVE-2023-46219
Summary
| CVE | CVE-2023-46219 |
|---|---|
| State | PUBLISHED |
| Assigner | hackerone |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-12-12 02:15:06 UTC |
| Updated | 2026-05-12 11:16:14 UTC |
| Description | When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS: 0.001270000 probability, percentile 0.315730000 (date 2026-05-12)
Problem Types: CWE-311 | CWE-311 CWE-311 Missing Encryption of Sensitive Data
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | ADP | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 38 | All | All | All |
| Application | Haxx | Curl | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Curl | Curl | affected 8.4.0 8.4.0 semver | Not specified |
| CNA | Curl | Curl | unaffected 7.84.0 7.84.0 semver | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIPLUS S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SINEC NMS | affected V3.0 SP1 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.netapp.com/advisory/ntap-20240119-0007 | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | |
| www.debian.org/security/2023/dsa-5587 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| cert-portal.siemens.com/productcert/html/ssa-082556.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| cert-portal.siemens.com/productcert/html/ssa-331112.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| lists.fedoraproject.org/archives/list/[email protected]/messag... | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| curl.se/docs/CVE-2023-46219.html | af854a3a-2127-422b-91ae-364da2661108 | curl.se | Vendor Advisory |
| cert-portal.siemens.com/productcert/html/ssa-093430.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| hackerone.com/reports/2236133 | af854a3a-2127-422b-91ae-364da2661108 | hackerone.com | Exploit, Third Party Advisory |
| lists.fedoraproject.org/archives/list/[email protected]/messag... | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199983 Ubuntu Security Notification for curl Vulnerability (USN-6535-1)
- 243077 Red Hat Update for JBoss Core Services (RHSA-2024:1316)
- 284810 Fedora Security Update for curl (FEDORA-2023-2121eca964)
- 285105 Fedora Security Update for curl (FEDORA-2023-9de8973300)
- 503683 Alpine Linux Security Update for curl
- 505865 Alpine Linux Security Update for curl
- 6000401 Debian Security Update for curl (DSA 5587-1)
- 673340 EulerOS Security Update for curl (EulerOS-SA-2024-1310)
- 673407 EulerOS Security Update for curl (EulerOS-SA-2024-1233)
- 673697 EulerOS Security Update for curl (EulerOS-SA-2024-1211)
- 673830 EulerOS Security Update for curl (EulerOS-SA-2024-1332)
- 755454 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:4659-1)
- 755457 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:4653-1)
- 907719 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (32120-1)