CVE-2023-46218

Name
CVE-2023-46218
Description
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
support@hackerone.com https://curl.se/docs/CVE-2023-46218.html
support@hackerone.com https://hackerone.com/reports/2212193
support@hackerone.com https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3ZX3VW67N4ACRAPMV2QS2LVYGD7H2MVE/
support@hackerone.com https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UOGXU25FMMT2X6UUITQ7EZZYMJ42YWWD/
support@hackerone.com https://lists.debian.org/debian-lts-announce/2023/12/msg00015.html
support@hackerone.com https://www.debian.org/security/2023/dsa-5587
support@hackerone.com https://security.netapp.com/advisory/ntap-20240125-0007/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* curl >= 7.46.0 <= 8.4.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
curl 3.16-main 8.5.0-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
curl 3.15-main 8.5.0-r0 Natanael Copa <ncopa@alpinelinux.org> fixed