CVE-2023-46218: Medium severity F5 BIG-IP Next vulnerability
cURL libcurl could allow a remote attacker to bypass security restrictions, caused by a mixed case flaw when curl is built without PSL support. By sending a specially crafted request, an attacker could exploit this vulnerability to allow a HTTP server to set "super cookies" in curl.
Other sources
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains.
It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with domain=co.UK when the URL used a lower case hostname curl.co.uk, even though co.uk is listed as a PSL domain.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 7.74.0-1.3+deb11u13Fixed in 7.74.0-1.3+deb11u11Fixed in 7.88.1-10+deb12u7Fixed in 7.88.1-10+deb12u5Fixed in 8.9.1-2Fixed in 8.10.1-1 - Upgrade
Upgrade
F5 BIG-IP Next (LTM)to a version that resolves this vulnerability.Fixed in 20.1.0 - Upgrade
Upgrade
F5 BIG-IP Next Central Managerto a version that resolves this vulnerability.Fixed in 20.1.0 - Upgrade
Upgrade
redhat/curlto a version that resolves this vulnerability.Fixed in 8.5.0
Event History
Frequently Asked Questions
What is CVE-2023-46218?
CVE-2023-46218 is a vulnerability related to cookie handling in the curl library, which allows for a mixed case Public Suffix List (PSL) bypass.
What is the severity of CVE-2023-46218?
The severity of CVE-2023-46218 is not specified in the provided information.
Which software is affected by CVE-2023-46218?
The affected software is 'curl' with versions up to exclusive 8.5.0 on Ubuntu, and versions up to inclusive 7.64.0-4+deb10u2, 7.64.0-4+deb10u7, 7.74.0-1.3+deb11u9, 7.74.0-1.3+deb11u10, 7.88.1-10+deb12u3, 7.88.1-10+deb12u4, and 8.4.0-2 on Debian.
How do I fix the CVE-2023-46218 vulnerability on Ubuntu?
To fix the CVE-2023-46218 vulnerability on Ubuntu, update the 'curl' package to version 8.5.0 or later.
How do I fix the CVE-2023-46218 vulnerability on Debian?
There is no specific remedy mentioned for the CVE-2023-46218 vulnerability on Debian. Consider monitoring the official Debian security advisories for updates or contact the package maintainers for more information.