MEDIUM · 5.3

CVE-2021-22923

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to ea...

Vulnerability Description

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HaxxCurl>= 7.27.0, < 7.78.0
FedoraprojectFedora33
NetappCloud Backup-
NetappClustered Data Ontap-
NetappHci Management Node-
NetappSolidfire-
OracleMysql Server>= 5.7.0, <= 5.7.35
SiemensSinec Infrastructure Network Services< 1.0.1.1
NetappH300S Firmware-
NetappH300S-
NetappH500S Firmware-
NetappH500S-
NetappH700S Firmware-
NetappH700S-
NetappH300E Firmware-
NetappH300E-
NetappH500E Firmware-
NetappH500E-
NetappH700E Firmware-
NetappH700E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-22923?

CVE-2021-22923 is a vulnerability with a CVSS score of 5.3 (MEDIUM). When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to ea...

How severe is CVE-2021-22923?

CVE-2021-22923 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-22923?

Check the references section above for vendor advisories and patch information. Affected products include: Haxx Curl, Fedoraproject Fedora, Netapp Cloud Backup, Netapp Clustered Data Ontap, Netapp Hci Management Node.