A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.
2018-08-01T06:29:00.287
2024-11-21T02:59:41.003
Modified
CVSSv3.0: 3.7 (LOW)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9