ZeroHour

CVE-2022-32208

PoC
CVSS 3.1
5.9 medium
EPSS
7%p94
Published
()
Modified
Description

When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.

Vendors
haxxfedoraprojectdebiannetappapplesplunk
Products
curl, fedora, debian linux, clustered data ontap, element software, hci management node, solidfire, bootstrap os, h300s firmware, h500s firmware, h700s firmware, h410s firmware
Weakness
CWE-840, CWE-787
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.