MEDIUM · 5.3

CVE-2021-22897

curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The se...

Vulnerability Description

curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if an application sets up multiple concurrent transfers, the last one that sets the ciphers will accidentally control the set used by all transfers. In a worst-case scenario, this weakens transport security significantly.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HaxxCurl>= 7.61.0, <= 7.76.1
OracleCommunications Cloud Native Core Binding Support Function1.11.0
OracleCommunications Cloud Native Core Network Function Cloud Native Environment1.10.0
OracleCommunications Cloud Native Core Network Repository Function1.15.0
OracleCommunications Cloud Native Core Network Slice Selection Function1.8.0
OracleCommunications Cloud Native Core Service Communication Proxy1.15.0
OracleEssbase< 11.1.2.4.047
OracleMysql Server<= 5.7.34
NetappCloud Backup-
NetappSolidfire\, Enterprise Sds \& Hci Storage Node-
NetappSolidfire \& Hci Management Node-
NetappSolidfire Baseboard Management Controller Firmware-
NetappHci Compute Node Firmware-
NetappHci Compute Node-
NetappH300E Firmware-
NetappH300E-
NetappH300S Firmware-
NetappH300S-
NetappH410S Firmware-
NetappH410S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-22897?

CVE-2021-22897 is a vulnerability with a CVSS score of 5.3 (MEDIUM). curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The se...

How severe is CVE-2021-22897?

CVE-2021-22897 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-22897?

Check the references section above for vendor advisories and patch information. Affected products include: Haxx Curl, Oracle Communications Cloud Native Core Binding Support Function, Oracle Communications Cloud Native Core Network Function Cloud Native Environment, Oracle Communications Cloud Native Core Network Repository Function, Oracle Communications Cloud Native Core Network Slice Selection Function.