[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2022-35252Date: (C)2022-09-12   (M)2024-05-24


When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 3.7CVSS Score :
Exploit Score: 2.2Exploit Score:
Impact Score: 1.4Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector:
Attack Complexity: HIGHAccess Complexity:
Privileges Required: NONEAuthentication:
User Interaction: NONEConfidentiality:
Scope: UNCHANGEDIntegrity:
Confidentiality: NONEAvailability:
Integrity: NONE 
Availability: LOW 
  
Reference:
http://seclists.org/fulldisclosure/2023/Jan/20
http://seclists.org/fulldisclosure/2023/Jan/21
GLSA-202212-01
https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html
https://hackerone.com/reports/1613943
https://security.netapp.com/advisory/ntap-20220930-0005/
https://support.apple.com/kb/HT213603
https://support.apple.com/kb/HT213604

OVAL    25
oval:org.secpod.oval:def:87035
oval:org.secpod.oval:def:2600210
oval:org.secpod.oval:def:507761
oval:org.secpod.oval:def:707693
...

© SecPod Technologies