CVE Vulnerabilities

CVE-2022-32207

Published: Jul 07, 2022 | Modified: Apr 23, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
9.8 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally widen the permissions for the target file, leaving the updated file accessible to more users than intended.

Affected Software

NameVendorStart VersionEnd Version
CurlHaxx7.69.0 (including)7.84.0 (excluding)
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-curl-0:7.86.0-2.el8jbcs*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-curl-0:7.86.0-2.el7jbcs*
Red Hat Enterprise Linux 9RedHatcurl-0:7.76.1-14.el9_0.5*
Red Hat Enterprise Linux 9RedHatcurl-0:7.76.1-14.el9_0.5*
Text-Only JBCSRedHatjbcs-httpd24-curl*
CurlUbuntudevel*
CurlUbuntuimpish*
CurlUbuntujammy*
CurlUbuntukinetic*
CurlUbuntuupstream*

References