CVE-2020-8177Resource Injection in Curl

Severity
7.8HIGHNVD
OSV7.5
EPSS
0.0%
top 94.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 14
Latest updateApr 16

Description

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages12 packages

Debianhaxx/curl< 7.72.0-1+3
Ubuntuhaxx/curl< 7.47.0-1ubuntu2.15+3
NVDhaxx/curl7.20.07.70.0
CVEListV5https/github.com_curl_curlcurl 7.20.0 to and including 7.70.0
NVDfujitsu/m10-1_firmware< xcp2410+1

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

5
VulDB
curl up to 7.70.0 File Name injection (Nessus ID 236591)2026-04-16
GHSA
GHSA-wqc8-jpfx-w9g4: curl 72022-05-24
CVEList
CVE-2020-8177: curl 72020-12-14
OSV
CVE-2020-8177: curl 72020-12-14
OSV
curl vulnerabilities2020-06-24

📋Vendor Advisories

4
Microsoft
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.2020-12-08
Ubuntu
curl vulnerabilities2020-06-24
Red Hat
curl: Incorrect argument check can allow remote servers to overwrite local files2020-06-24
Debian
CVE-2020-8177: curl - curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for fi...2020

💬Community

6
HackerOne
CVE-2020-8177: curl overwrite local file with -J2020-12-05
Bugzilla
CVE-2020-8177 curl: command line arguments lead to local file overwrite [fedora-all]2020-06-26
Bugzilla
CVE-2020-8177 flickcurl: curl: command line arguments lead to local file overwrite [fedora-all]2020-06-26
Bugzilla
CVE-2020-8177 mingw-curl: curl: command line arguments lead to local file overwrite [fedora-all]2020-06-26
Bugzilla
CVE-2020-8177 flickcurl: curl: command line arguments lead to local file overwrite [epel-7]2020-06-26
CVE-2020-8177 — Resource Injection in Haxx Curl | cvebase