Insecurely generated cookies In curl
Description
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains.
It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with domain=co.UK when the URL used a lower
case hostname curl.co.uk, even though co.uk is listed as a PSL domain.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.15 | 8.5.0-r0 | ||
alpine v3.16 | 8.5.0-r0 | ||
alpine v3.17 | 8.5.0-r0 | ||
alpine v3.18 | 8.5.0-r0 | ||
alpine v3.19 | 8.5.0-r0 | ||
alpine v3.20 | 8.5.0-r0 | ||
alpine v3.21 | 8.5.0-r0 | ||
alpine v3.22 | 8.5.0-r0 | ||
debian 12 | 7.88.1-10+deb12u5 | ||
debian 13 | 8.5.0-1 |
1-10 of 19
10
Aliases