CVE-2022-27775

Published Jun 2, 2022

Last updated 12 days ago

Overview

Description
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
Source
support@hackerone.com
NVD status
Modified
Products
curl, debian_linux, hci_bootstrap_os, clustered_data_ontap, solidfire_\&_hci_management_node, solidfire_\&_hci_storage_node, fabric_operating_system, h300s_firmware, h500s_firmware, h700s_firmware, h410s_firmware, universal_forwarder

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

CVSS 2.0

Type
Primary
Base score
5
Impact score
2.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

support@hackerone.com
CWE-200
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Configurations