CVE Vulnerabilities

CVE-2014-3620

Published: Nov 18, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

Affected Software

NameVendorStart VersionEnd Version
CurlHaxx*7.37.1 (including)
CurlHaxx7.31.0 (including)7.31.0 (including)
CurlHaxx7.32.0 (including)7.32.0 (including)
CurlHaxx7.33.0 (including)7.33.0 (including)
CurlHaxx7.34.0 (including)7.34.0 (including)
CurlHaxx7.35.0 (including)7.35.0 (including)
CurlHaxx7.36.0 (including)7.36.0 (including)
CurlHaxx7.37.0 (including)7.37.0 (including)
CurlUbuntudevel*
CurlUbuntuesm-infra-legacy/trusty*
CurlUbuntutrusty*
CurlUbuntutrusty/esm*
CurlUbuntuupstream*

References