A flaw was found in the Curl package, where the HSTS mechanism could fail when multiple transfers are done in parallel, as the HSTS cache file gets overwritten by the most recently completed transfer. This issue may result in limited confidentiality and integrity.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Core | curl | 2023-03-02 22:36 | ALAS2-2023-1986 |
Amazon Linux 2023 | curl | 2023-02-21 16:43 | ALAS2023-2023-114 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 3.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N |
NVD | CVSSv3 | 6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |