Fiche vulnérabilité
CVE-2022-27782 : faille élevée haxx curl (CVSS 7.5)
Description
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 2 juin 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- haxx curl
- debian debian linux
- splunk universal forwarder