ZeroHour

CVE-2022-32207

PoC
CVSS 3.1
9.8 critical
EPSS
7%p94
Published
()
Modified
Description

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

Vendors
haxxfedoraprojectdebiannetappapplesplunk
Products
curl, fedora, debian linux, clustered data ontap, element software, hci management node, solidfire, bootstrap os, h300s firmware, h500s firmware, h700s firmware, h410s firmware
Weakness
CWE-840, CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.