AZL-34618
Dashboard / Vulnerabilities / AZL-34618
Summary: CVE-2023-46218 affecting package cmake for versions less than 3.29.6-1
Details: This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-46218
Affected packages
Package
Name: cmake
Purl: pkg:rpm/azure-linux/cmake
Affected ranges
Type: ECOSYSTEM
Events:
