When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2022-07-07T00:00:00

Updated: 2024-08-03T07:32:56.011Z

Reserved: 2022-06-01T00:00:00

Link: CVE-2022-32207

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-07-07T13:15:08.403

Modified: 2024-03-27T15:00:46.637

Link: CVE-2022-32207

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-06-27T00:00:00Z

Links: CVE-2022-32207 - Bugzilla