CVE-2023-28321: Race Condition
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
Credit
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-28321?
CVE-2023-28321 is an improper certificate validation vulnerability in curl.
Which versions of curl are affected by CVE-2023-28321?
Versions of curl prior to 8.1.0 are affected by CVE-2023-28321.
What is the severity of CVE-2023-28321?
CVE-2023-28321 has a high severity with a CVSS score of 7.
How can I fix CVE-2023-28321?
To fix CVE-2023-28321, update to curl version 8.1.0 or later.
Where can I find more information about CVE-2023-28321?
You can find more information about CVE-2023-28321 at the following references: <ul><li><a href="https://hackerone.com/reports/1950627">HackerOne Report</a></li><li><a href="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F4I75RDGX5ULSSCBE5BF3P5I5SFO7ULQ/">Fedora Security Announcement 1</a></li><li><a href="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z2LIWHWKOVH24COGGBCVOWDXXIUPKOMK/">Fedora Security Announcement 2</a></li></ul>