CVE-2021-22946
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
- Affected products
- Alt Linux, Astra Linux, Centos, Linuxmint, Apple Macos, Mysql Server, Red Hat, Rocky Linux
- Haxx Curl
- < 7.79.0
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 4.5% (91th percentile)
- Weakness
- CWE-325, CWE-319
- NVD status
- Modified
- Published
- 2021-09-29
No indexed exploits for CVE-2021-22946 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-22946 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.