ZeroHour

CVE-2022-27775

PoC
CVSS 3.1
7.5 high
EPSS
3%p87
Published
()
Modified
Description

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

Vendors
haxxdebiannetappbrocadesplunk
Products
curl, debian linux, hci bootstrap os, clustered data ontap, solidfire \& hci management node, solidfire \& hci storage node, fabric operating system, h300s firmware, h500s firmware, h700s firmware, h410s firmware, universal forwarder
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.