curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if an application sets up multiple concurrent transfers, the last one that sets the ciphers will accidentally control the set used by all transfers. In a worst-case scenario, this weakens transport security significantly.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Aug 22, 2024 | Jun 11, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libcurl-develUpgrade curlUpgrade libcurl | Aug 10, 2021 | Jun 11, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade curlUpgrade libcurl | Aug 10, 2021 | Jun 11, 2021 |
| Oracle Solaris | — | Upgrade web/curl to version 7.79.0-11.4.39.0.1.107.0 on Solaris 11.4 | Nov 17, 2021 | Jun 11, 2021 |
| Splunk | — | Upgrade Splunk Universal Forwarder to version 9.1.1Upgrade Splunk Universal Forwarder to version 8.2.12Upgrade Splunk Enterprise to version 8.2.11Upgrade Splunk Universal Forwarder to version 8.1.14Upgrade Splunk Enterprise to version 8.2.12Upgrade Splunk Universal Forwarder to version 8.2.11Upgrade Splunk Enterprise to version 8.1.14Upgrade Splunk Universal Forwarder to version 9.0.6Upgrade Splunk Enterprise to version 9.1.1Upgrade Splunk Enterprise to version 9.0.5Upgrade Splunk Universal Forwarder to version 9.0.5Upgrade Splunk Enterprise to version 9.0.6 | Sep 30, 2025 | Jun 11, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 11, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub