When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2022-07-07T00:00:00
Updated: 2024-08-03T07:32:56.011Z
Reserved: 2022-06-01T00:00:00
Link: CVE-2022-32207
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-07-07T13:15:08.403
Modified: 2024-03-27T15:00:46.637
Link: CVE-2022-32207
Redhat