LOW · 3.7

CVE-2021-22924

libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take ...

Vulnerability Description

libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.

CVSS Score

3.7

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HaxxLibcurl>= 7.10.4, < 7.77.0
FedoraprojectFedora33
DebianDebian Linux9.0
NetappCloud Backup-
NetappClustered Data Ontap-
NetappSolidfire \& Hci Management Node-
NetappSolidfire Baseboard Management Controller Firmware-
OracleMysql Server>= 5.7.0, <= 5.7.36
OraclePeoplesoft Enterprise Peopletools8.57
SiemensSinec Infrastructure Network Services< 1.0.1.1
SiemensSinema Remote Connect Server< 3.1
SiemensLogo\! Cmr2040 FirmwareAll versions
SiemensLogo\! Cmr2040-
SiemensLogo\! Cmr2020 FirmwareAll versions
SiemensLogo\! Cmr2020-
SiemensRuggedcomrm 1224 Lte Firmware< 7.1
SiemensRuggedcomrm 1224 Lte-
SiemensScalance M804Pb Firmware< 7.1
SiemensScalance M804Pb-
SiemensScalance M812-1 Firmware< 7.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-22924?

CVE-2021-22924 is a vulnerability with a CVSS score of 3.7 (LOW). libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take ...

How severe is CVE-2021-22924?

CVE-2021-22924 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-22924?

Check the references section above for vendor advisories and patch information. Affected products include: Haxx Libcurl, Fedoraproject Fedora, Debian Debian Linux, Netapp Cloud Backup, Netapp Clustered Data Ontap.