CVE-2023-46218
07.12.2023, 01:15
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| haxx | curl | 7.46.0 ≤ 𝑥 ≤ 8.4.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Siemens | SIMATIC S7-1500 CPU 1518-4 PN\/DP MFP | V3.1.5 ≤ 𝑥 < * | ADP |
| Siemens | SIMATIC S7-1500 CPU 1518-4 PN\/DP MFP | V3.1.5 ≤ 𝑥 < * | ADP |
| Siemens | SIMATIC S7-1500 CPU 1518F-4 PN\/DP MFP | V3.1.5 ≤ 𝑥 < * | ADP |
| Siemens | SIMATIC S7-1500 CPU 1518F-4 PN\/DP MFP | V3.1.5 ≤ 𝑥 < * | ADP |
| Siemens | SIPLUS S7-1500 CPU 1518-4 PN\/DP MFP | V3.1.5 ≤ 𝑥 < * | ADP |
| Siemens | RUGGEDCOM ROX MX5000 | 𝑥 < V2.17.0 | ADP |
| Siemens | RUGGEDCOM ROX MX5000RE | 𝑥 < V2.17.0 | ADP |
| Siemens | RUGGEDCOM ROX RX1400 | 𝑥 < V2.17.0 | ADP |
| Siemens | RUGGEDCOM ROX RX1500 | 𝑥 < V2.17.0 | ADP |
| Siemens | RUGGEDCOM ROX RX1501 | 𝑥 < V2.17.0 | ADP |
| Siemens | RUGGEDCOM ROX RX1510 | 𝑥 < V2.17.0 | ADP |
| Siemens | RUGGEDCOM ROX RX1511 | 𝑥 < V2.17.0 | ADP |
| Siemens | RUGGEDCOM ROX RX1512 | 𝑥 < V2.17.0 | ADP |
| Siemens | RUGGEDCOM ROX RX1524 | 𝑥 < V2.17.0 | ADP |
| Siemens | RUGGEDCOM ROX RX1536 | 𝑥 < V2.17.0 | ADP |
| Siemens | RUGGEDCOM ROX RX5000 | 𝑥 < V2.17.0 | ADP |
| Siemens | SINEC NMS | 𝑥 < V3.0 SP1 | ADP |
| curl | curl | 𝑥 ≤ 8.4.0 | CNA |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| curl |
| ||||||||||||||||||||||||||||||
| libcurl-devel |
| ||||||||||||||||||||||||||||||
| libcurl4 |
| ||||||||||||||||||||||||||||||
| libcurl4-32bit |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| curl |
| ||||||||||||||||||||
| curl-minimal |
| ||||||||||||||||||||
| libcurl |
| ||||||||||||||||||||
| libcurl-devel |
| ||||||||||||||||||||
| libcurl-minimal |
|
Common Weakness Enumeration
References