Data Protection Advisor 是否受 libcurl 7.9.1 和 8.4.0 Cookie 注入影响

Summary: libcurl 7.9.1 和 8.4.0 Cookie 注入是否会影响 Data Protection Advisor (DPA)?

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

安全扫描程序报告 DPA 代理

上的“libcurl 7.9.1 8.4.0 Cookie 注入”。 受影响的路径:
/opt/emc/dpa/agent/lib/libcurl.so.4
安装的版本:
  • 7.47.1
修复版本:
  • 8.4.0

Cause

出现此漏洞的原因是使用了以下 API:
"curl_easy_duphandle".
此漏洞描述如下:CVE-2023-38546:
Cookie 注入,无文件
  此超链接会将您带往 Dell Technologies 之外的网站。

Resolution

根据 DPA 工程,DPA 代理服务和 DPA 不使用此 API。此漏洞不会影响 DPA 或 DPA 代理程序服务。无需执行任何操作。 

Affected Products

Data Protection Advisor
Article Properties
Article Number: 000221431
Article Type: Solution
Last Modified: 01 Feb 2024
Version:  2
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.