Vulnerability CVE-2022-30115: Information

Description

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.

Severity: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Published: June 2, 2022
Modified: March 27, 2024
Error type identifier: CWE-319

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
curlsisyphus7.83.1-alt18.7.1-alt2ALT-PU-2022-1837-1299767Fixed
curlsisyphus_e2k7.83.1-alt18.7.1-alt2ALT-PU-2022-4933-1-Fixed
curlsisyphus_riscv647.83.1-alt18.7.1-alt2ALT-PU-2022-4929-1-Fixed
curlp107.83.1-alt18.7.1-alt1ALT-PU-2022-1902-1299735Fixed
curlp10_e2k7.83.1-alt18.7.1-alt1ALT-PU-2022-5004-1-Fixed
curlc10f17.83.1-alt18.6.0-alt1ALT-PU-2022-1902-1299735Fixed
curlc9f27.83.1-alt18.6.0-alt1ALT-PU-2022-1877-1299774Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
      Start including
      7.82.0
      End excliding
      7.83.1

      Configuration 2

      cpe:2.3:o:netapp:hci_bootstrap_os:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*

      cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*

      cpe:2.3:a:netapp:solidfire\,_enterprise_sds_\&_hci_storage_node:-:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

      Configuration 5

      cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

      Configuration 6

      cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

      Configuration 7

      cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

      Configuration 8

      cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*

      cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*
      Start including
      9.0.0
      End excliding
      9.0.6

      cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*
      Start including
      8.2.0
      End excliding
      8.2.12