Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46236
HistoryApr 05, 2024 - 8:04 p.m.

Logic Error

2024-04-0520:04:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
curl
vulnerability
logic error
protocol restriction
software

3.5 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.3%

curl is vulnerable to Logic Error. The vulnerability is due to an error in the logic for removing protocols when a protocol selection parameter option disables all protocols without adding any, allows attackers to potentially bypass protocol restrictions and perform requests with disabled protocols.

3.5 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.3%