PT-2022-6538 · Curl+10 · Curl+9

Kurohiro

·

Published

2022-10-29

·

Updated

2026-05-18

·

CVE-2022-43551

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions curl versions prior to 7.87.0 MySQL Server versions 5.7.41 and earlier, 8.0.32 and earlier
Description A vulnerability exists in the HSTS check of curl that could be bypassed to trick it into keeping using HTTP. The HSTS mechanism could be bypassed if the host name in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. This could allow a remote attacker to gain unauthorized access to protected information. The issue is related to the storage of IDN encoded information but looking for it IDN decoded, leading to a clear text transfer in subsequent requests.
Recommendations For curl versions prior to 7.87.0, update to version 7.87.0 or later to resolve the issue. For MySQL Server versions 5.7.41 and earlier, 8.0.32 and earlier, update to a version that includes the fix for this vulnerability. As a temporary workaround, consider disabling the HSTS support in curl until a patch is available. Restrict access to the vulnerable curl functionality to minimize the risk of exploitation.

Exploit

Fix

DoS

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3379
ALT-PU-2022-3439
ALT-PU-2023-5727
ALT-PU-2023-7320
ALT-PU-2023-7463
ALT-PU-2023-7647
ALT-PU-2023-7888
AZL-12107
AZL-12930
AZL-34616
AZL-38788
BDU:2023-02157
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2022-43551
MGASA-2022-0483
OESA-2023-1007
OESA-2023-1834
OESA-2023-1835
OESA-2023-1836
OESA-2024-2071
OPENSUSE-SU-2022_4597-1
OPENSUSE-SU-2024:12583-1
RHSA-2023:3354
SUSE-SU-2022:4597-1
SUSE-SU-2022_4597-1
USN-5788-1

Affected Products

Alt Linux
Debian
Ibm Aix
Linuxmint
Apple Macos
Mysql Server
Red Os
Suse
Ubuntu
Curl