Vulnerability Description
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Haxx | Curl | >= 7.77.0, < 7.88.0 |
| Netapp | Active Iq Unified Manager | - |
| Netapp | Clustered Data Ontap | 9.0 |
| Netapp | H300S Firmware | - |
| Netapp | H300S | - |
| Netapp | H500S Firmware | - |
| Netapp | H500S | - |
| Netapp | H700S Firmware | - |
| Netapp | H700S | - |
| Netapp | H410S Firmware | - |
| Netapp | H410S | - |
| Splunk | Universal Forwarder | >= 8.2.0, < 8.2.12 |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/1813864ExploitIssue Tracking
- https://security.gentoo.org/glsa/202310-12Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230309-0006/Third Party Advisory
- https://hackerone.com/reports/1813864ExploitIssue Tracking
- https://security.gentoo.org/glsa/202310-12Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230309-0006/Third Party Advisory
FAQ
What is CVE-2023-23914?
CVE-2023-23914 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl...
How severe is CVE-2023-23914?
CVE-2023-23914 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-23914?
Check the references section above for vendor advisories and patch information. Affected products include: Haxx Curl, Netapp Active Iq Unified Manager, Netapp Clustered Data Ontap, Netapp H300S Firmware, Netapp H300S.