CVE-2022-30115PoC(haxx / clustered_data_ontap)

LOWCVSS 4.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-325CWE-319

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • clustered_data_ontap
  • curl
  • h300s
  • h300s_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
clustered_data_ontapcurlh300sh300s_firmwareh410sh410s_firmwareh500sh500s_firmwareh700sh700s_firmware

2 versions affected across 15 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-18: 1PoC Mentioned / Linked · 2026-05-18: 1Technical Details · 2026-05-18: 105-18
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • H1 Disclosed - Public Disclosures@h1Disclosed
    PoC

    ⚡ HSTS multi-trailing-dot bypass-ish: possible incomplete fix for CVE-2022-30115 👨🏻‍💻 giant_anteater ➟ curl 🟧 Medium 💰 None 🔗 https://hackerone.com/reports/3733984 #bugbounty #bugbountytips #cybersecurity #infosec https://t.co/um3rpJtrF0

    Post summary

    The tweet alerts to a possible incomplete fix for CVE-2022-30115 involving an HSTS multi-trailing-dot bypass, with PoC details referenced via a HackerOne report.

    10010405
    10.2K followersView on X
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---
Appnetappclustered_data_ontap---
HWnetapph300s---
OSnetapph300s_firmware---
HWnetapph410s---
OSnetapph410s_firmware---
HWnetapph500s---
OSnetapph500s_firmware---
HWnetapph700s---
OSnetapph700s_firmware---
OSnetapphci_bootstrap_os---
HWnetapphci_compute_node---
Appnetappsolidfire\,_enterprise_sds_\&_hci_storage_node---
Appnetappsolidfire_\&_hci_management_node---
Appsplunkuniversal_forwarder---
Appsplunkuniversal_forwarder9.1.0--

Explore more