CRITICAL 9.1 Microsoft

CVE-2023-23914

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

Microsoft Security Update 2023-Feb: A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.

Affected Products

References

Published: 2023-02-14 · Source: Microsoft · Feed updated: 2026-08-20
This critical severity vulnerability with a CVSS score of 9.1 was published on 2023-02-14 via Microsoft. Affected: cbl2 tensorflow 2.11.1-2 on CBL Mariner 2.0, azl3 rust 1.86.0-1 on Azure Linux 3.0, azl3 rust 1.75.0-14 on Azure Linux 3.0 and 5 more.

Risk Timeline

CVE Disclosed2023-02-14 · 1283 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2025-62878Local Path Provisioner vulnerable to Path Traversal via parameters.pathPatternCRITICAL9.9
CVE-2021-20231A flaw was found in gnutls. A use after free issue in client sending key_share eCRITICAL9.8
CVE-2021-20232A flaw was found in gnutls. A use after free issue in client_send_params in lib/CRITICAL9.8
CVE-2023-20032On Feb 15 2023 the following vulnerability in the ClamAV scanning library was diCRITICAL9.8
CVE-2022-48337GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacCRITICAL9.8
CVE-2025-0665eventfd double closeCRITICAL9.8
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.