An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).
2022-05-26T17:15:09.077
2024-11-21T06:47:03.447
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | haxx | curl | < 7.83.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |
Application | netapp | clustered_data_ontap | - | Yes |
Application | netapp | solidfire_\&_hci_management_node | - | Yes |
Application | netapp | solidfire_\&_hci_storage_node | - | Yes |
Operating System | brocade | fabric_operating_system | - | Yes |
Operating System | netapp | bootstrap_os | - | Yes |
Hardware | netapp | hci_compute_node | - | No |
Operating System | netapp | h300s_firmware | - | Yes |
Hardware | netapp | h300s | - | No |
Operating System | netapp | h500s_firmware | - | Yes |
Hardware | netapp | h500s | - | No |
Operating System | netapp | h700s_firmware | - | Yes |
Hardware | netapp | h700s | - | No |
Operating System | netapp | h410s_firmware | - | Yes |
Hardware | netapp | h410s | - | No |
Application | splunk | universal_forwarder | < 8.2.12 | Yes |
Application | splunk | universal_forwarder | < 9.0.6 | Yes |
Application | splunk | universal_forwarder | 9.1.0 | Yes |