PT-2022-6536 · Curl+6 · Curl+6
Nyymi
·
Published
2022-12-21
·
Updated
2026-05-18
·
CVE-2023-23914
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
curl versions prior to 7.88.0
Description
A cleartext transmission of sensitive information issue exists in curl that could cause HSTS functionality to fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However, this HSTS mechanism would be ignored by subsequent transfers when done on the same command line because the state would not be properly carried on. The issue can be reproduced by requesting multiple URLs serially, such as
https://curl.se followed by http://curl.se, where the second URL fails to take advantage of the HSTS information returned by the first URL.Recommendations
For versions prior to 7.88.0, update to version 7.88.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of multiple URLs in the same command line to minimize the risk of exploitation. Restrict access to sensitive information and use HTTPS instead of HTTP to reduce the risk of cleartext transmission of sensitive information.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu
Curl