CVE-2022-32207 is a critical vulnerability affecting curl versions prior to 7.84.0, where an atomic file rename operation for saving cookies, alt-svc, or hsts data can inadvertently widen file permissions, making sensitive data accessible to unauthorized users. This flaw impacts numerous products including Apple, Debian, Fedora, Haxx, NetApp, and Splunk. With a CVSS score of 9.8 (CRITICAL), it presents a high risk due to its network attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, the vulnerability has garnered limited community discussion and media coverage, indicating a lower current threat but still requiring attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.69.0, < 7.84.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
August Third Party Package Updates in Splunk Universal Forwarder
Aug 30, 2023When curl < 7.84.0 saves cookies alt-svc and hsts data to local files it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation it might accidentally *widen* the permissions for the target file leaving the updated file accessible to more users than intended.
Jul 12, 2022curl: Unpreserved file permissions
Jun 27, 2022Non-preserved file permissions
Jun 27, 2022