Ist Data Protection Advisor von libcurl 7.9.1 8.4.0 Cookie-Injektion betroffen?
Summary: Hat libcurl 7.9.1 8.4.0 Cookie Injection Auswirkungen auf Data Protection Advisor (DPA)?
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
Der Sicherheitsscanner meldet "libcurl 7.9.1 8.4.0 Cookie Injection" auf einem DPA-Agenten.
Betroffener Pfad:
Betroffener Pfad:
/opt/emc/dpa/agent/lib/libcurl.so.4Installierte Version:
- 7.47.1
- 8.4.0
Cause
Diese Sicherheitslücke tritt aufgrund der Verwendung der API auf:
Cookie-Injektion ohne Datei
"curl_easy_duphandle".Diese Sicherheitslücke wird unter folgendem Pfad CVE-2023-38546 beschrieben:
Cookie-Injektion ohne Datei
Resolution
Gemäß DPA-Engineering verwenden DPA-Agent-Services und DPA diese API nicht. Diese Sicherheitslücke hat keine Auswirkungen auf DPA- oder DPA-Agent-Services. sind keine weiteren Maßnahmen erforderlich.
Affected Products
Data Protection AdvisorArticle Properties
Article Number: 000221431
Article Type: Solution
Last Modified: 01 Feb 2024
Version: 2
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.