peter bassill · operator
$ cve CVE-2022-32207 JSON

CVE-2022-32207

9.8
CRITICAL · CVSS 3.1 · EPSS 7.7% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.74% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-840
On CISA KEVno
Public exploitnone known
Published2022-07-07
Last modified2026-06-17

Affected (19)

VendorProduct
applemacos
debiandebian linux
fedoraprojectfedora
haxxcurl
netappbootstrap os
netappclustered data ontap
netappelement software
netapph300s
netapph300s firmware
netapph410s
netapph410s firmware
netapph500s
netapph500s firmware
netapph700s
netapph700s firmware
netapphci compute node
netapphci management node
netappsolidfire
splunkuniversal forwarder

References

→ the Explorer  ·  watch your stack  ·  NVD