CVE-2021-22890

Related Vulnerabilities: CVE-2021-22890  

A flaw was found in curl. When confusing the tickets, a HTTPS proxy can trick libcurl to use the wrong session ticket resume for the host and thereby circumvent the server TLS certificate check and make a MITM attack to be possible to perform unnoticed.

Description

A flaw was found in curl. When confusing the tickets, a HTTPS proxy can trick libcurl to use the wrong session ticket resume for the host and thereby circumvent the server TLS certificate check and make a MITM attack to be possible to perform unnoticed.

Additional Information

  • Bugzilla 1941965: CVE-2021-22890 curl: TLS 1.3 session ticket mix-up with HTTPS proxy host
  • CWE-290: Authentication Bypass by Spoofing
  • FAQ: Frequently asked questions about CVE-2021-22890