AZL-32126
Dashboard / Vulnerabilities / AZL-32126
Summary: CVE-2023-46218 affecting package mysql for versions less than 8.0.35-2
Details: This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-46218
Affected packages
Package
Name: mysql
Purl: pkg:rpm/azure-linux/mysql
Affected ranges
Type: ECOSYSTEM
Events:
