DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2023-46218

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-46218

CGA ID

CGA-qhgc-2ghx-hfhx

Severity

6.5

Medium

CVSS V3

Description

This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains.

It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with domain=co.UK when the URL used a lower case hostname curl.co.uk, even though co.uk is listed as a PSL domain.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images