libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask for the client certificate by name or with a file name - using the same option. If the name exists as a file, it will be used instead of by name.If the appliction runs with a current working directory that is writable by other users (like `/tmp`), a malicious user can create a file name with the same name as the app wants to use by name, and thereby trick the application to use the file based cert instead of the one referred to by name making libcurl send the wrong client certificate in the TLS connection handshake.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Haxx
Subscribe
|
Curl
Subscribe
|
|
Netapp
Subscribe
|
Active Iq Unified Manager
Subscribe
Clustered Data Ontap
Subscribe
H300e
Subscribe
H300e Firmware
Subscribe
H300s
Subscribe
H300s Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500e
Subscribe
H500e Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H700e
Subscribe
H700e Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Hci Management Node
Subscribe
Oncommand Insight
Subscribe
Oncommand Workflow Automation
Subscribe
Snapcenter
Subscribe
Solidfire
Subscribe
|
|
Oracle
Subscribe
|
|
|
Siemens
Subscribe
|
Sinec Infrastructure Network Services
Subscribe
|
|
Splunk
Subscribe
|
Universal Forwarder
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-03T18:58:25.857Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-22926
No data.
Status : Modified
Published: 2021-08-05T21:15:11.553
Modified: 2024-11-21T05:50:56.047
Link: CVE-2021-22926
OpenCVE Enrichment
No data.