← Back

CVE-2023-46219

nvd nist
Published: Dec 12, 2023Modified: May 12, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

Affected (2)

Products: Haxx: Curl · Fedoraproject: Fedora
1 product
Curl
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 7.84.0 to 8.5.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 38

References (14)

Source: support@hackerone.com
Vendor Advisory
Source: support@hackerone.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e

Timeline

No history available yet.