跳转到帖子

FreeBSD: VID-BE233FC6-BAE7-11ED-A4FB-080027F5FEC9 (CVE-2023-23914): curl -- multiple vulnerabilities

recommended_posts

发布于
  • Members

FreeBSD: VID-BE233FC6-BAE7-11ED-A4FB-080027F5FEC9 (CVE-2023-23914): curl -- multiple vulnerabilities

Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:N)
Published
02/15/2023
Created
03/08/2023
Added
03/06/2023
Modified
01/28/2025

Description

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

Solution(s)

  • freebsd-upgrade-package-curl

References

  • CVE-2023-23914
  • 查看数 694
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…