ZeroHour

CVE-2022-35252

PoC
CVSS 3.1
3.7 low
EPSS
2%p79
Published
()
Modified
Description

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

Vendors
haxxnetappappledebiansplunk
Products
curl, clustered data ontap, element software, hci management node, solidfire, bootstrap os, h300s firmware, h500s firmware, h700s firmware, h410s firmware, macos, debian linux
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.