Aller au contenu

Fiche vulnérabilité

CVE-2022-27782 : faille élevée haxx curl (CVSS 7.5)

Description

libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
2 juin 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • haxx curl
  • debian debian linux
  • splunk universal forwarder

Références

Rechercher une autre vulnérabilité dans la base CVE