Medium severity4.3NVD Advisory· Published Jun 2, 2022· Updated Jun 17, 2026
CVE-2022-30115
CVE-2022-30115
Description
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2022/10/26/4nvdMailing ListPatchThird Party Advisory
- hackerone.com/reports/1557449nvdExploitThird Party Advisory
- www.openwall.com/lists/oss-security/2022/12/21/1nvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202212-01nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20220609-0009/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.