UBUNTU-CVE-2022-27780

    Dashboard / Vulnerabilities / UBUNTU-CVE-2022-27780

    UBUNTU-CVE-2022-27780

    Published: 11 May 2022Last Modified: 22 Apr 2026
    Upstream:
    Aliases:

    Summary:

    Details: The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe parser and get transposed into `http://example.com/127.0.0.1/`. This flawcan be used to circumvent filters, checks and more.

    Affected packages

    Package

    Name: curl

    Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=jammy

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -7.81.0-1ubuntu1.2

    Affected versions

    7.74.0-1.3ubuntu2
    7.74.0-1.3ubuntu3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    UBUNTU-CVE-2022-27780 | CVE-DB