PT-2022-2697 · Curl+2 · Curl+2

Haxatron1

·

Published

2022-01-27

·

Updated

2026-05-18

·

CVE-2022-30115

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions cURL (affected versions not specified)
Description The issue is related to the implementation of the HSTS (HTTP Strict Transport Security) mechanism in the cURL utility. It could be bypassed if the hostname in the given URL used a trailing dot while not using one when it built the HSTS cache, or the other way around. This could allow an attacker to intercept traffic and gain unauthorized access to protected information. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1837
ALT-PU-2022-1877
ALT-PU-2022-1902
AZL-9891
BDU:2022-03187
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2022-30115
OPENSUSE-SU-2024:12062-1

Affected Products

Alt Linux
Red Os
Curl