Description
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
References (16)
Core 16
Core References
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/
Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Mar/29
Third Party Advisory vendor-advisory
https://www.debian.org/security/2022/dsa-5197
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202212-01
Patch, Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
Exploit, Issue Tracking, Patch, Third Party Advisory
https://hackerone.com/reports/1334111
Third Party Advisory
https://security.netapp.com/advisory/ntap-20211029-0003/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20220121-0008/
Release Notes, Third Party Advisory
https://support.apple.com/kb/HT213183
Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Scores
CVSS v3
7.5
EPSS
0.0006
EPSS Percentile
19.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-319
CWE-325
Status
published
Products (40)
None/https://github.com/curl/curl
curl 7.20.0 to and including 7.78.0
apple/macos
< 12.3
debian/debian_linux
9.0
debian/debian_linux
10.0
debian/debian_linux
11.0
fedoraproject/fedora
33
fedoraproject/fedora
35
haxx/curl
7.20.0 - 7.79.0
netapp/cloud_backup
netapp/clustered_data_ontap
... and 30 more
Published
Sep 29, 2021
Tracked Since
Feb 18, 2026