CVE-2022-27782

HIGH

curl < 7.83.1 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.

References (6)

Core 6
Core References
Mailing List, Third Party Advisory vendor-advisory
https://www.debian.org/security/2022/dsa-5197
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202212-01
Exploit, Third Party Advisory
https://hackerone.com/reports/1555796

Scores

CVSS v3 7.5
EPSS 0.0047
EPSS Percentile 64.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-295 CWE-840
Status published
Products (6)
None/https://github.com/curl/curl Fixed in 7.83.1
debian/debian_linux 10.0
debian/debian_linux 11.0
haxx/curl < 7.83.1
splunk/universal_forwarder 9.1.0
splunk/universal_forwarder 8.2.0 - 8.2.12
Published Jun 02, 2022
Tracked Since Feb 18, 2026