CVE-2021-22890
Description
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server and then wrongly "short-cut" the host handshake. When confusing the tickets, a HTTPS proxy can trick libcurl to use the wrong session ticket resume for the host and thereby circumvent the server TLS certificate check and make a MITM attack to be possible to perform unnoticed. Note that such a malicious HTTPS proxy needs to provide a certificate that curl will accept for the MITMed server for an attack to work - unless curl has been told to ignore the server certificate check.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- curl/curldescription
- osv-coords5 versionspkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/curl-mini&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.0pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2
< 7.66.0-lp152.3.15.1+ 4 more
- (no CPE)range: < 7.66.0-lp152.3.15.1
- (no CPE)range: < 7.79.1-1.1
- (no CPE)range: < 7.66.0-lp152.3.15.1
- (no CPE)range: < 7.66.0-4.14.1
- (no CPE)range: < 7.66.0-4.14.1
Patches
Vulnerability mechanics
References
9- cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfnvdPatchThird Party Advisory
- curl.se/docs/CVE-2021-22890.htmlnvdPatchVendor Advisory
- hackerone.com/reports/1129529nvdExploitIssue TrackingPatchThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ZC5BMIOKLBQJSFCHEDN2G2C2SH274BP/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITVWPVGLFISU5BJC2BXBRYSDXTXE2YGC/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQUIOYX2KUU6FIUZVB5WWZ6JHSSYSQWJ/nvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202105-36nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20210521-0007/nvdThird Party Advisory
- www.oracle.com//security-alerts/cpujul2021.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.