CVE-2022-27775
Last modified
CVE-2022-27775 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.. EPSS estimates a 2.79% chance of exploitation in the next 30 days.
Description
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Haxx | Curl | >= 7.65.0, <= 7.82.0 |
| Debian | Debian Linux | 11.0 |
| Netapp | Hci Bootstrap Os | All versions |
| Netapp | Clustered Data Ontap | All versions |
| Netapp | Solidfire \& Hci Management Node | All versions |
| Netapp | Solidfire \& Hci Storage Node | All versions |
| Brocade | Fabric Operating System | All versions |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H410s Firmware | All versions |
| Splunk | Universal Forwarder | >= 8.2.0, < 8.2.12 |
| Splunk | Universal Forwarder | >= 9.0.0, < 9.0.6 |
| Splunk | Universal Forwarder | 9.1.0 |
References
- https://hackerone.com/reports/1546268Exploit, Third Party Advisory
- https://security.gentoo.org/glsa/202212-01Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220609-0008/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5197Third Party Advisory
- https://hackerone.com/reports/1546268Exploit, Third Party Advisory
- https://security.gentoo.org/glsa/202212-01Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220609-0008/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5197Third Party Advisory
- https://hackerone.com/reports/1546268Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-27775?
How severe is CVE-2022-27775?
How do I fix CVE-2022-27775?
Are you affected by CVE-2022-27775?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
