Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-35252

EPSS 0.36% · P58
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-35252

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
输入验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
curl 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
curl是一款用于从服务器传输数据或向服务器传输数据的工具。 curl 4.9 到 7.84版本存在安全漏洞,该漏洞源于当 curl 从 HTTP(S) 服务器检索和解析 cookie 时,它​​使用控制代码(小于 32 的字节值)接受 cookie,当包含此类控制代码的 cookie 稍后被发送回 HTTP(S) 服务器时,它可能会使服务器返回 400 响应。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-https://github.com/curl/curl Fixed in curl 7.85.0 -

II. Public POCs for CVE-2022-35252

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-35252

登录查看更多情报信息。

Same Patch Batch · n/a · 2022-09-23 · 79 CVEs total

CVE-2022-35246Rocket.Chat 安全漏洞
CVE-2022-35248Rocket.Chat 授权问题漏洞
CVE-2022-32220Rocket.Chat 信息泄露漏洞
CVE-2022-35250Rocket.Chat 安全漏洞
CVE-2022-35251Rocket.Chat 跨站脚本漏洞
CVE-2022-35249Rocket.Chat 信息泄露漏洞
CVE-2022-35893Insyde InsydeH2O 输入验证错误漏洞
CVE-2022-40359Google KFM 跨站脚本漏洞
CVE-2022-40358Pydio 跨站脚本漏洞
CVE-2022-36338Insyde InsydeH2O 安全漏洞
CVE-2022-32218Rocket.Chat 信息泄露漏洞
CVE-2022-32226Rocket.Chat 输入验证错误漏洞
CVE-2022-32227Rocket.Chat 信息泄露漏洞
CVE-2022-32228Rocket.Chat 安全漏洞
CVE-2022-32229Rocket.Chat 安全漏洞
CVE-2022-35247Rocket.Chat 安全漏洞
CVE-2022-30124Rocket.Chat 授权问题漏洞
CVE-2022-32211Rocket.Chat SQL注入漏洞
CVE-2022-32217Rocket.Chat 日志信息泄露漏洞
CVE-2022-32219Rocket.Chat 信息泄露漏洞

Showing top 20 of 79 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2022-35252

No comments yet


Leave a comment