cbcvebase.
CVE-2023-27534
published 2023-03-30

CVE-2023-27534: A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the…

PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.20%
80.2th percentile
A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debiancurl< curl 7.88.1-7 (bookworm)curl 7.88.1-7 (bookworm)
fedoraprojectfedora
haxxcurl>= 0 < 7.74.0-1.3+deb11u87.74.0-1.3+deb11u8
haxxcurl>= 0 < 7.88.1-77.88.1-7
haxxcurl>= 0 < 7.88.1-77.88.1-7
haxxcurl>= 0 < 7.88.1-77.88.1-7
haxxcurl>= 0 < 7.58.0-2ubuntu3.247.58.0-2ubuntu3.24
haxxcurl>= 0 < 7.68.0-1ubuntu2.187.68.0-1ubuntu2.18
haxxcurl>= 0 < 7.81.0-1ubuntu1.107.81.0-1ubuntu1.10
haxxcurl7.18.0 – 7.88.1
httpsgithub.com_curl_curl
msrcazl3_cmake_3.21.4-10_on_azure_linux_3.0
msrcazl3_cmake_3.28.2-1_on_azure_linux_3.0
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.11.1-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_cmake_3.21.4-12_on_cbl_mariner_2.0
msrccbl2_curl_8.0.1-1_on_cbl_mariner_2.0
msrccbl2_mysql_8.0.34-1_on_cbl_mariner_2.0
msrccbl2_rust_1.72.0-2_on_cbl_mariner_2.0
msrccbl2_tensorflow_2.11.1-2_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_oracle8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.