MEDIUM · 6.5

CVE-2021-22922

When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to g...

Vulnerability Description

When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several of them. In a serial orparallel manner.If one of the servers hosting the contents has been breached and the contentsof the specific file on that server is replaced with a modified payload, curlshould detect this when the hash of the file mismatches after a completeddownload. It should remove the contents and instead try getting the contentsfrom another URL. This is not done, and instead such a hash mismatch is onlymentioned in text and the potentially malicious content is kept in the file ondisk.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
HaxxCurl>= 7.27.0, < 7.78.0
FedoraprojectFedora33
NetappCloud Backup-
NetappClustered Data Ontap-
NetappHci Management Node-
NetappSolidfire-
OracleMysql Server>= 5.7.0, <= 5.7.35
SiemensSinec Infrastructure Network Services< 1.0.1.1
NetappH300S Firmware-
NetappH300S-
NetappH500S Firmware-
NetappH500S-
NetappH700S Firmware-
NetappH700S-
NetappH300E Firmware-
NetappH300E-
NetappH500E Firmware-
NetappH500E-
NetappH700E Firmware-
NetappH700E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-22922?

CVE-2021-22922 is a vulnerability with a CVSS score of 6.5 (MEDIUM). When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to g...

How severe is CVE-2021-22922?

CVE-2021-22922 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-22922?

Check the references section above for vendor advisories and patch information. Affected products include: Haxx Curl, Fedoraproject Fedora, Netapp Cloud Backup, Netapp Clustered Data Ontap, Netapp Hci Management Node.