CVE Vulnerabilities

CVE-2023-46218

Published: Dec 07, 2023 | Modified: Jun 30, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

This flaw allows a malicious HTTP server to set super cookies in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains.

It could do this by exploiting a mixed case flaw in curls function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with domain=co.UK when the URL used a lower case hostname curl.co.uk, even though co.uk is listed as a PSL domain.

Affected Software

NameVendorStart VersionEnd Version
CurlHaxx7.46.0 (including)8.4.0 (including)
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-curl-0:8.6.0-3.el8jbcs*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-curl-0:8.6.0-3.el7jbcs*
Red Hat Enterprise Linux 8RedHatcurl-0:7.61.1-33.el8_9.5*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatcurl-0:7.61.1-22.el8_6.12*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatcurl-0:7.61.1-30.el8_8.9*
Red Hat Enterprise Linux 9RedHatcurl-0:7.76.1-26.el9_3.3*
Red Hat Enterprise Linux 9RedHatcurl-0:7.76.1-26.el9_3.3*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatcurl-0:7.76.1-14.el9_0.11*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatcurl-0:7.76.1-23.el9_2.6*
RHODF-4.15-RHEL-9RedHatodf4/cephcsi-rhel9:v4.15.0-37*
RHODF-4.15-RHEL-9RedHatodf4/mcg-core-rhel9:v4.15.0-68*
RHODF-4.15-RHEL-9RedHatodf4/mcg-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/mcg-rhel9-operator:v4.15.0-39*
RHODF-4.15-RHEL-9RedHatodf4/ocs-client-console-rhel9:v4.15.0-58*
RHODF-4.15-RHEL-9RedHatodf4/ocs-client-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/ocs-client-rhel9-operator:v4.15.0-13*
RHODF-4.15-RHEL-9RedHatodf4/ocs-metrics-exporter-rhel9:v4.15.0-81*
RHODF-4.15-RHEL-9RedHatodf4/ocs-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/ocs-rhel9-operator:v4.15.0-79*
RHODF-4.15-RHEL-9RedHatodf4/odf-cli-rhel9:v4.15.0-22*
RHODF-4.15-RHEL-9RedHatodf4/odf-console-rhel9:v4.15.0-57*
RHODF-4.15-RHEL-9RedHatodf4/odf-cosi-sidecar-rhel9:v4.15.0-6*
RHODF-4.15-RHEL-9RedHatodf4/odf-csi-addons-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/odf-csi-addons-rhel9-operator:v4.15.0-15*
RHODF-4.15-RHEL-9RedHatodf4/odf-csi-addons-sidecar-rhel9:v4.15.0-15*
RHODF-4.15-RHEL-9RedHatodf4/odf-multicluster-console-rhel9:v4.15.0-54*
RHODF-4.15-RHEL-9RedHatodf4/odf-multicluster-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/odf-multicluster-rhel9-operator:v4.15.0-10*
RHODF-4.15-RHEL-9RedHatodf4/odf-must-gather-rhel9:v4.15.0-26*
RHODF-4.15-RHEL-9RedHatodf4/odf-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/odf-rhel9-operator:v4.15.0-19*
RHODF-4.15-RHEL-9RedHatodf4/odr-cluster-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/odr-hub-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/odr-rhel9-operator:v4.15.0-21*
RHODF-4.15-RHEL-9RedHatodf4/rook-ceph-rhel9-operator:v4.15.0-103*
RHOL-5.6-RHEL-8RedHatopenshift-logging/cluster-logging-operator-bundle:v5.6.18-16*
RHOL-5.6-RHEL-8RedHatopenshift-logging/cluster-logging-rhel8-operator:v5.6.18-7*
RHOL-5.6-RHEL-8RedHatopenshift-logging/elasticsearch6-rhel8:v6.8.1-409*
RHOL-5.6-RHEL-8RedHatopenshift-logging/elasticsearch-operator-bundle:v5.6.18-16*
RHOL-5.6-RHEL-8RedHatopenshift-logging/elasticsearch-proxy-rhel8:v1.0.0-481*
RHOL-5.6-RHEL-8RedHatopenshift-logging/elasticsearch-rhel8-operator:v5.6.18-7*
RHOL-5.6-RHEL-8RedHatopenshift-logging/eventrouter-rhel8:v0.4.0-246*
RHOL-5.6-RHEL-8RedHatopenshift-logging/fluentd-rhel8:v1.14.6-216*
RHOL-5.6-RHEL-8RedHatopenshift-logging/kibana6-rhel8:v6.8.1-430*
RHOL-5.6-RHEL-8RedHatopenshift-logging/log-file-metric-exporter-rhel8:v1.1.0-226*
RHOL-5.6-RHEL-8RedHatopenshift-logging/logging-curator5-rhel8:v5.8.1-472*
RHOL-5.6-RHEL-8RedHatopenshift-logging/logging-loki-rhel8:v2.9.6-16*
RHOL-5.6-RHEL-8RedHatopenshift-logging/logging-view-plugin-rhel8:v5.6.18-3*
RHOL-5.6-RHEL-8RedHatopenshift-logging/loki-operator-bundle:v5.6.18-30*
RHOL-5.6-RHEL-8RedHatopenshift-logging/loki-rhel8-operator:v5.6.18-12*
RHOL-5.6-RHEL-8RedHatopenshift-logging/lokistack-gateway-rhel8:v0.1.0-528*
RHOL-5.6-RHEL-8RedHatopenshift-logging/opa-openshift-rhel8:v0.1.0-226*
RHOL-5.6-RHEL-8RedHatopenshift-logging/vector-rhel8:v0.21.0-127*
RHOL-5.7-RHEL-8RedHatopenshift-logging/cluster-logging-operator-bundle:v5.7.13-16*
RHOL-5.7-RHEL-8RedHatopenshift-logging/cluster-logging-rhel8-operator:v5.7.13-7*
RHOL-5.7-RHEL-8RedHatopenshift-logging/elasticsearch6-rhel8:v6.8.1-408*
RHOL-5.7-RHEL-8RedHatopenshift-logging/elasticsearch-operator-bundle:v5.7.13-19*
RHOL-5.7-RHEL-8RedHatopenshift-logging/elasticsearch-proxy-rhel8:v1.0.0-480*
RHOL-5.7-RHEL-8RedHatopenshift-logging/elasticsearch-rhel8-operator:v5.7.13-9*
RHOL-5.7-RHEL-8RedHatopenshift-logging/eventrouter-rhel8:v0.4.0-248*
RHOL-5.7-RHEL-8RedHatopenshift-logging/fluentd-rhel8:v1.14.6-215*
RHOL-5.7-RHEL-8RedHatopenshift-logging/kibana6-rhel8:v6.8.1-431*
RHOL-5.7-RHEL-8RedHatopenshift-logging/log-file-metric-exporter-rhel8:v1.1.0-228*
RHOL-5.7-RHEL-8RedHatopenshift-logging/logging-curator5-rhel8:v5.8.1-471*
RHOL-5.7-RHEL-8RedHatopenshift-logging/logging-loki-rhel8:v2.9.6-15*
RHOL-5.7-RHEL-8RedHatopenshift-logging/logging-view-plugin-rhel8:v5.7.13-3*
RHOL-5.7-RHEL-8RedHatopenshift-logging/loki-operator-bundle:v5.7.13-27*
RHOL-5.7-RHEL-8RedHatopenshift-logging/loki-rhel8-operator:v5.7.13-12*
RHOL-5.7-RHEL-8RedHatopenshift-logging/lokistack-gateway-rhel8:v0.1.0-527*
RHOL-5.7-RHEL-8RedHatopenshift-logging/opa-openshift-rhel8:v0.1.0-225*
RHOL-5.7-RHEL-8RedHatopenshift-logging/vector-rhel8:v0.28.1-57*
RHOL-5.8-RHEL-9RedHatopenshift-logging/cluster-logging-operator-bundle:v5.8.6-22*
RHOL-5.8-RHEL-9RedHatopenshift-logging/cluster-logging-rhel9-operator:v5.8.6-11*
RHOL-5.8-RHEL-9RedHatopenshift-logging/elasticsearch6-rhel9:v6.8.1-407*
RHOL-5.8-RHEL-9RedHatopenshift-logging/elasticsearch-operator-bundle:v5.8.6-19*
RHOL-5.8-RHEL-9RedHatopenshift-logging/elasticsearch-proxy-rhel9:v1.0.0-479*
RHOL-5.8-RHEL-9RedHatopenshift-logging/elasticsearch-rhel9-operator:v5.8.6-7*
RHOL-5.8-RHEL-9RedHatopenshift-logging/eventrouter-rhel9:v0.4.0-247*
RHOL-5.8-RHEL-9RedHatopenshift-logging/fluentd-rhel9:v5.8.6-5*
RHOL-5.8-RHEL-9RedHatopenshift-logging/log-file-metric-exporter-rhel9:v1.1.0-227*
RHOL-5.8-RHEL-9RedHatopenshift-logging/logging-curator5-rhel9:v5.8.1-470*
RHOL-5.8-RHEL-9RedHatopenshift-logging/logging-loki-rhel9:v2.9.6-14*
RHOL-5.8-RHEL-9RedHatopenshift-logging/logging-view-plugin-rhel9:v5.8.6-2*
RHOL-5.8-RHEL-9RedHatopenshift-logging/loki-operator-bundle:v5.8.6-24*
RHOL-5.8-RHEL-9RedHatopenshift-logging/loki-rhel9-operator:v5.8.6-10*
RHOL-5.8-RHEL-9RedHatopenshift-logging/lokistack-gateway-rhel9:v0.1.0-525*
RHOL-5.8-RHEL-9RedHatopenshift-logging/opa-openshift-rhel9:v0.1.0-224*
RHOL-5.8-RHEL-9RedHatopenshift-logging/vector-rhel9:v0.28.1-56*
Text-Only JBCSRedHatjbcs-httpd24-curl*
CurlUbuntubionic*
CurlUbuntudevel*
CurlUbuntuesm-infra/bionic*
CurlUbuntuesm-infra/focal*
CurlUbuntuesm-infra/xenial*
CurlUbuntufocal*
CurlUbuntujammy*
CurlUbuntulunar*
CurlUbuntumantic*
CurlUbuntutrusty*
CurlUbuntuupstream*
CurlUbuntuxenial*

References