CVE-2022-27780
PoC —CVSS 3.1
7.5 high
EPSS
2%p84
Published
()
Modified
Description
The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe parser and get transposed into `http://example.com/127.0.0.1/`. This flawcan be used to circumvent filters, checks and more.
- Vendors
- haxxnetappsplunk
- Products
- curl, hci bootstrap os, clustered data ontap, solidfire\, enterprise sds \& hci storage node, solidfire \& hci management node, h410s firmware, h700s firmware, h500s firmware, h300s firmware, universal forwarder
- Weakness
- CWE-177, CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.