Er Data Protection Advisor påvirket af libcurl 7.9.1 8.4.0 Cookie injektion

Summary: Påvirker libcurl 7.9.1 8.4.0 injektion af cookies Data Protection Advisor (DPA)?

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Security scanner rapporterer "libcurl 7.9.1 8.4.0 Cookie Injection"  på en DPA-agent.

Berørt sti:
/opt/emc/dpa/agent/lib/libcurl.so.4
Installeret version:
  • 7.47.1
Fast version:
  • 8.4.0

Cause

Denne sårbarhed opstår på grund af brugen af API'en:
"curl_easy_duphandle".
Denne sårbarhed er beskrevet på:CVE-2023-38546:
Cookie injektion med ingen fil
  Dette hyperlink fører dig til et websted uden for Dell Technologies.

Resolution

I henhold til DPA-teknikken bruger DPA-agenttjenester og DPA ikke denne API. Denne sårbarhed påvirker ikke DPA- eller DPA-agenttjenester. Så kræves der ingen handling. 

Affected Products

Data Protection Advisor
Article Properties
Article Number: 000221431
Article Type: Solution
Last Modified: 01 Feb 2024
Version:  2
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.