K000138650 : cURL vulnerability CVE-2023-46218
Discription

Security Advisory Description This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with domain=co**.**UK when the URL used a lower case hostname curl**.**co**.**uk, even though co**.**uk is listed as a PSL domain. (CVE-2023-46218) Impact The affected F5 products are not using the cURL library or binary in a vulnerable way. However, the F5 product can be vulnerable when custom scripts are used to accept super cookies and exposed to this…Read More

Back to Main

Subscribe for the latest news: