Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-35252
Description:When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2022.2815   1.3.6.1.4.1.25623.1.1.4.2022.3003.1   1.3.6.1.4.1.25623.1.0.854946   1.3.6.1.4.1.25623.1.0.822471   1.3.6.1.4.1.25623.1.1.2.2022.2722   1.3.6.1.4.1.25623.1.1.2.2023.1164   1.3.6.1.4.1.25623.1.0.822398   1.3.6.1.4.1.25623.1.1.4.2022.3004.1   1.3.6.1.4.1.25623.1.1.2.2023.1143   1.3.6.1.4.1.25623.1.0.822482   1.3.6.1.4.1.25623.1.1.10.2022.0333   1.3.6.1.4.1.25623.1.1.4.2022.3005.1   1.3.6.1.4.1.25623.1.0.845501   1.3.6.1.4.1.25623.1.1.2.2023.1216   1.3.6.1.4.1.25623.1.1.2.2022.2757   1.3.6.1.4.1.25623.1.1.13.2022.243.01   1.3.6.1.4.1.25623.1.1.2.2022.2840   1.3.6.1.4.1.25623.1.1.2.2023.1186   1.3.6.1.4.1.25623.1.0.854941   1.3.6.1.4.1.25623.1.1.2.2022.2790  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-35252
http://seclists.org/fulldisclosure/2023/Jan/20
http://seclists.org/fulldisclosure/2023/Jan/21
https://security.gentoo.org/glsa/202212-01
https://hackerone.com/reports/1613943
https://hackerone.com/reports/1613943
https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html




© 1998-2025 E-Soft Inc. All rights reserved.