CVE-2021-22898

Source
https://cve.org/CVERecord?id=CVE-2021-22898
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-22898.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-22898
Aliases
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CLEANSTART (6)
CLSA (3)
DEBIAN (1)
JLSEC (1)
MGASA (1)
OESA (1)
openSUSE (3)
RHSA (1)
RLSA (1)
SUSE (6)
UBUNTU (1)
Related
Published
2021-06-11T16:15:11Z
Modified
2026-05-16T04:03:02Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

curl 7.7 through 7.76.1 suffers from an information disclosure when the -t command line option, known as CURLOPT_TELNETOPTIONS in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "last_affected":  "9.0"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "debian:debian_linux"
        },
        {
            "cpes":  [
                "cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*",
                "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "last_affected":  "33"
                },
                {
                    "last_affected":  "34"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "fedoraproject:fedora"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.11.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "last_affected":  "1.11.0"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "oracle:communications_cloud_native_core_binding_support_function"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "last_affected":  "1.10.0"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "oracle:communications_cloud_native_core_network_function_cloud_native_environment"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.1:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "last_affected":  "1.15.0"
                },
                {
                    "last_affected":  "1.15.1"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "oracle:communications_cloud_native_core_network_repository_function"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "last_affected":  "1.8.0"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "oracle:communications_cloud_native_core_network_slice_selection_function"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.15.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "last_affected":  "1.15.0"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "oracle:communications_cloud_native_core_service_communication_proxy"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:essbase:*:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "fixed":  "11.1.2.4.047"
                },
                {
                    "introduced":  "21.0"
                },
                {
                    "fixed":  "21.3"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "oracle:essbase"
        },
        {
            "cpes":  [
                "cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "fixed":  "1.0.1.1"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "siemens:sinec_infrastructure_network_services"
        },
        {
            "cpes":  [
                "cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*",
                "cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "8.2.0"
                },
                {
                    "fixed":  "8.2.12"
                },
                {
                    "introduced":  "9.0.0"
                },
                {
                    "fixed":  "9.0.6"
                },
                {
                    "last_affected":  "9.1.0"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "splunk:universal_forwarder"
        }
    ]
}
References

Affected packages