CVE Vulnerabilities

CVE-2022-22576

Improper Authentication

Published: May 26, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
8.1 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Curl Haxx 7.33.0 (including) 7.83.0 (excluding)
Red Hat Enterprise Linux 8 RedHat curl-0:7.61.1-22.el8_6.3 *
Red Hat Enterprise Linux 9 RedHat curl-0:7.76.1-14.el9_0.4 *
Red Hat Enterprise Linux 9 RedHat curl-0:7.76.1-14.el9_0.4 *
Curl Ubuntu bionic *
Curl Ubuntu devel *
Curl Ubuntu esm-infra-legacy/trusty *
Curl Ubuntu esm-infra/xenial *
Curl Ubuntu focal *
Curl Ubuntu impish *
Curl Ubuntu jammy *
Curl Ubuntu trusty/esm *
Curl Ubuntu upstream *

Potential Mitigations

References