CRITICAL 9.1 Microsoft
CVE-2023-23914
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.
Microsoft Security Update 2023-Feb: A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.
Affected Products
- cbl2 tensorflow 2.11.1-2 on CBL Mariner 2.0
- azl3 rust 1.86.0-1 on Azure Linux 3.0
- azl3 rust 1.75.0-14 on Azure Linux 3.0
- cm1 rust 1.59.0-1 on CBL Mariner 1.0
- cm1 mysql 8.0.32-1 on CBL Mariner 1.0
- cm1 curl 7.88.1-1 on CBL Mariner 1.0
- cm1 cmake 3.21.4-3 on CBL Mariner 1.0
- cbl2 rust 1.68.2-5 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23914
- https://nvd.nist.gov/vuln/detail/CVE-2023-23914
This critical severity vulnerability with a CVSS score of 9.1 was published on 2023-02-14 via Microsoft. Affected: cbl2 tensorflow 2.11.1-2 on CBL Mariner 2.0, azl3 rust 1.86.0-1 on Azure Linux 3.0, azl3 rust 1.75.0-14 on Azure Linux 3.0 and 5 more.
Risk Timeline
CVE Disclosed2023-02-14 · 1283 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23914NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2023-23914Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2025-62878 | Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern | CRITICAL | 9.9 |
| CVE-2021-20231 | A flaw was found in gnutls. A use after free issue in client sending key_share e | CRITICAL | 9.8 |
| CVE-2021-20232 | A flaw was found in gnutls. A use after free issue in client_send_params in lib/ | CRITICAL | 9.8 |
| CVE-2023-20032 | On Feb 15 2023 the following vulnerability in the ClamAV scanning library was di | CRITICAL | 9.8 |
| CVE-2022-48337 | GNU Emacs through 28.2 allows attackers to execute commands via shell metacharac | CRITICAL | 9.8 |
| CVE-2025-0665 | eventfd double close | CRITICAL | 9.8 |
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.