cbcvebase.
CVE-2023-27535
published 2023-03-30

CVE-2023-27535: An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during…

PriorityP335medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.61%
72.8th percentile
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debiancurl< curl 7.88.1-7 (bookworm)curl 7.88.1-7 (bookworm)
debiandebian_linux
fedoraprojectfedora
haxxcurl>= 0 < 7.74.0-1.3+deb11u87.74.0-1.3+deb11u8
haxxcurl>= 0 < 7.88.1-77.88.1-7
haxxcurl>= 0 < 7.88.1-77.88.1-7
haxxcurl>= 0 < 7.88.1-77.88.1-7
haxxcurl>= 0 < 7.58.0-2ubuntu3.247.58.0-2ubuntu3.24
haxxcurl>= 0 < 7.68.0-1ubuntu2.187.68.0-1ubuntu2.18
haxxcurl>= 0 < 7.81.0-1ubuntu1.107.81.0-1ubuntu1.10
haxxcurl>= 0 < 7.35.0-1ubuntu2.20+esm157.35.0-1ubuntu2.20+esm15
haxxcurl>= 0 < 7.47.0-1ubuntu2.19+esm87.47.0-1ubuntu2.19+esm8
haxxlibcurl7.13.0 – 7.88.1
httpsgithub.com_curl_curl
msrcazl3_cmake_3.21.4-10_on_azure_linux_3.0
msrcazl3_cmake_3.28.2-1_on_azure_linux_3.0
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.11.1-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_cmake_3.21.4-13_on_cbl_mariner_2.0
msrccbl2_curl_8.0.1-1_on_cbl_mariner_2.0
msrccbl2_mysql_8.0.34-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.