CVE-2023-23914

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:clustered_data_ontap:9.0:-:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

OR cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*

History

27 Mar 2024, 14:55

Type Values Removed Values Added
CPE cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*
First Time Splunk universal Forwarder
Splunk

09 Mar 2023, 19:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20230309-0006/ -

03 Mar 2023, 16:08

Type Values Removed Values Added
CWE CWE-319
CPE cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
References (MISC) https://hackerone.com/reports/1813864 - (MISC) https://hackerone.com/reports/1813864 - Exploit, Issue Tracking
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

23 Feb 2023, 22:58

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-23 20:15

Updated : 2024-03-27 14:55


NVD link : CVE-2023-23914

Mitre link : CVE-2023-23914

CVE.ORG link : CVE-2023-23914


JSON object : View

Products Affected

netapp

  • h300s
  • clustered_data_ontap
  • h300s_firmware
  • h500s
  • active_iq_unified_manager
  • h500s_firmware
  • h700s_firmware
  • h700s
  • h410s
  • h410s_firmware

haxx

  • curl

splunk

  • universal_forwarder
CWE
CWE-319

Cleartext Transmission of Sensitive Information