Description
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.
Published: 2021-08-05
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2734-1 curl security update
Debian DLA Debian DLA DLA-3085-1 curl security update
Debian DSA Debian DSA DSA-5197-1 curl security update
EUVD EUVD EUVD-2021-10053 libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.
Ubuntu USN Ubuntu USN USN-5021-1 curl vulnerabilities
History

Mon, 09 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Debian Debian Linux
Fedoraproject Fedora
Haxx Libcurl
Netapp Cloud Backup Clustered Data Ontap Solidfire \& Hci Management Node Solidfire Baseboard Management Controller Firmware
Oracle Mysql Server Peoplesoft Enterprise Peopletools
Redhat Enterprise Linux Rhel Dotnet
Siemens Logo\! Cmr2020 Logo\! Cmr2020 Firmware Logo\! Cmr2040 Logo\! Cmr2040 Firmware Ruggedcomrm 1224 Lte Ruggedcomrm 1224 Lte Firmware Scalance M804pb Scalance M804pb Firmware Scalance M812-1 Scalance M812-1 Firmware Scalance M816-1 Scalance M816-1 Firmware Scalance M826-2 Scalance M826-2 Firmware Scalance M874-2 Scalance M874-2 Firmware Scalance M874-3 Scalance M874-3 Firmware Scalance M876-3 Scalance M876-3 Firmware Scalance M876-4 Scalance M876-4 Firmware Scalance Mum856-1 Scalance Mum856-1 Firmware Scalance S615 Scalance S615 Firmware Simatic Cp 1543-1 Simatic Cp 1543-1 Firmware Simatic Cp 1545-1 Simatic Cp 1545-1 Firmware Simatic Rtu3010c Simatic Rtu3010c Firmware Simatic Rtu3030c Simatic Rtu3030c Firmware Simatic Rtu3031c Simatic Rtu3031c Firmware Simatic Rtu 3041c Simatic Rtu 3041c Firmware Sinec Infrastructure Network Services Sinema Remote Connect Sinema Remote Connect Server Siplus Net Cp 1543-1 Siplus Net Cp 1543-1 Firmware
Splunk Universal Forwarder
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-06-09T15:02:19.721Z

Reserved: 2021-01-06T00:00:00.000Z

Link: CVE-2021-22924

cve-icon Vulnrichment

Updated: 2024-08-03T18:58:25.955Z

cve-icon NVD

Status : Modified

Published: 2021-08-05T21:15:11.380

Modified: 2025-06-09T15:15:24.403

Link: CVE-2021-22924

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-07-21T06:00:00Z

Links: CVE-2021-22924 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses