SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22890

curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets.

LOW 3.7EPSS 3.14%

Does this matter?

Lower severity and a low EPSS score (3.14%). Track it; it rarely justifies an emergency change on its own.

Description

curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server and then wrongly "short-cut" the host handshake. When confusing the tickets, a HTTPS proxy can trick libcurl to use the wrong session ticket resume for the host and thereby circumvent the server TLS certificate check and make a MITM attack to be possible to perform unnoticed. Note that such a malicious HTTPS proxy needs to provide a certificate that curl will accept for the MITMed server for an attack to work - unless curl has been told to ignore the server certificate check.

CVSS 3.1
3.7 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
3.14% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-300, CWE-290
Affected
haxx/libcurl · fedoraproject/fedora · netapp/hci management node · netapp/solidfire · netapp/hci storage node · broadcom/fabric operating system · debian/debian linux · siemens/sinec infrastructure network services · oracle/communications billing and revenue management · oracle/essbase · splunk/universal forwarder
Source
support@hackerone.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.