CVE-2021-22923
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.
- Affected products
- Alt Linux, Astra Linux, Centos, Debian, Red Hat, Rocky Linux, Suse, Curl
- Haxx Curl
- < 7.78.0
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 1.8% (77th percentile)
- Weakness
- CWE-319, CWE-522
- NVD status
- Modified
- Published
- 2021-08-05
CVE-2021-22923 at NVD
No indexed exploits for CVE-2021-22923 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-22923 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.