An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 20
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Haxx Curl
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
|
7.33.0
|
7.83.0
|
|
Debian Debian_Linux
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
|
— | — |
|
Debian Debian_Linux
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
|
— | — |
|
Netapp Clustered_Data_Ontap
cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*
|
— | — |
|
Netapp Solidfire_\&_Hci_Management_Node
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
|
— | — |
|
Netapp Solidfire_\&_Hci_Storage_Node
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
|
— | — |
|
Brocade Fabric_Operating_System
cpe:2.3:o:brocade:fabric_operating_system:-:*:*:*:*:*:*:*
|
— | — |
|
Netapp Bootstrap_Os
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
|
— | — |
|
Netapp Hci_Compute_Node
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
|
— | — |
|
Netapp H300s_Firmware
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
|
— | — |
|
Netapp H300s
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
|
— | — |
|
Netapp H500s_Firmware
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
|
— | — |
|
Netapp H500s
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
|
— | — |
|
Netapp H700s_Firmware
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
|
— | — |
|
Netapp H700s
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
|
— | — |
|
Netapp H410s_Firmware
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
|
— | — |
|
Netapp H410s
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
|
— | — |
|
Splunk Universal_Forwarder
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*
|
8.2.0
|
8.2.12
|
|
Splunk Universal_Forwarder
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*
|
9.0.0
|
9.0.6
|
|
Splunk Universal_Forwarder
cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*
|
— | — |