Is Data Protection Advisor Impacted by libcurl 7.9.1 8.4.0 Cookie Injection
Summary: Does libcurl 7.9.1 8.4.0 Cookie Injection impact Data Protection Advisor (DPA)?
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
Security scanner reports "libcurl 7.9.1 8.4.0 Cookie Injection" on a DPA agent.
Affected Path:
Affected Path:
/opt/emc/dpa/agent/lib/libcurl.so.4Installed version:
- 7.47.1
- 8.4.0
Cause
This vulnerability arises due to use of the API:
CVE-2023-38546: Cookie injection with none file
"curl_easy_duphandle".This vulnerability is described at:
CVE-2023-38546: Cookie injection with none file
Resolution
As per DPA engineering, DPA agent services and DPA do not use this API. This vulnerability does not impact DPA or DPA agent services. No action is required.
Affected Products
Data Protection AdvisorArticle Properties
Article Number: 000221431
Article Type: Solution
Last Modified: 01 Feb 2024
Version: 2
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.