CVE-2023-46218

medium
Published 2024-03-05 · Modified 2024-04-02
CVSS v3
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v2
VIR risk
6.5

Description

Moderate: curl security and bug fix update

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-1601.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2241938

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2196793

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:1601

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-1129.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2252030

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2023-46218.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-46218

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:1601

vendor Authored 2026-05-27

Vendor advisory: support@hackerone.com — https://hackerone.com/reports/2212193

vendor Authored 2026-05-27

Vendor advisory: support@hackerone.com — https://curl.se/docs/CVE-2023-46218.html

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:1129

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
debian debianbookwormfixed7.88.1-10+deb12u5
debian debianbullseyefixed7.74.0-1.3+deb11u11
debian debianforkyfixed8.5.0-1
debian debiansidfixed8.5.0-1
debian debiantrixiefixed8.5.0-1
suse slesaffected
fedora fedora39affected

Application impact

VendorProductVersionsFixed
haxxcurl{"startIncluding":"7.46.0","endIncluding":"8.4.0"}

References

CWEs

CWE-178

Verify integrity in audit chain (admin only). AS-IS.