PT-2022-6536 · Curl+6 · Curl+6

Nyymi

·

Published

2022-12-21

·

Updated

2026-05-18

·

CVE-2023-23914

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions curl versions prior to 7.88.0
Description A cleartext transmission of sensitive information issue exists in curl that could cause HSTS functionality to fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However, this HSTS mechanism would be ignored by subsequent transfers when done on the same command line because the state would not be properly carried on. The issue can be reproduced by requesting multiple URLs serially, such as https://curl.se followed by http://curl.se, where the second URL fails to take advantage of the HSTS information returned by the first URL.
Recommendations For versions prior to 7.88.0, update to version 7.88.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of multiple URLs in the same command line to minimize the risk of exploitation. Restrict access to sensitive information and use HTTPS instead of HTTP to reduce the risk of cleartext transmission of sensitive information.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1252
ALT-PU-2023-1292
ALT-PU-2023-5727
AZL-13650
AZL-13654
AZL-34615
AZL-38043
BDU:2023-02154
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2023-23914
OESA-2023-1124
OESA-2023-1125
OPENSUSE-SU-2023_0429-1
OPENSUSE-SU-2024:12735-1
RHSA-2023:3354
SUSE-SU-2023:0429-1
SUSE-SU-2023_0429-1
USN-5891-1

Affected Products

Alt Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu
Curl