CVE-2023-46218

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/12/2023
Last modified:
12/05/2026

Description

This flaw allows a malicious HTTP server to set "super cookies" in curl that<br /> are then passed back to more origins than what is otherwise allowed or<br /> possible. This allows a site to set cookies that then would get sent to<br /> different and unrelated sites and domains.<br /> <br /> It could do this by exploiting a mixed case flaw in curl&amp;#39;s function that<br /> verifies a given cookie domain against the Public Suffix List (PSL). For<br /> example a cookie could be set with `domain=co.UK` when the URL used a lower<br /> case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* 7.46.0 (including) 8.4.0 (including)
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*