Логотип exploitDog
bind:CVE-2023-27538
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-27538

Количество 15

Количество 15

ubuntu логотип

CVE-2023-27538

почти 3 года назад

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2023-27538

почти 3 года назад

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-27538

почти 3 года назад

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-27538

почти 3 года назад

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2023-27538

почти 3 года назад

An authentication bypass vulnerability exists in libcurl prior to v8.0 ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-cgj3-cvg6-pcvh

почти 3 года назад

An authentication bypass vulnerability exists in libcurl v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2023-02103

почти 3 года назад

Уязвимость библиотеки libcurl, связанная с обходом процедуры аутентификации, позволяющая нарушителю повторно использовать неподходящее соединение

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20230407-21

почти 3 года назад

Множественные уязвимости curl

CVSS3: 5.9
EPSS: Низкий
oracle-oval логотип

ELSA-2023-6679

около 2 лет назад

ELSA-2023-6679: curl security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1582-1

почти 3 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0865-1

почти 3 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1711-1

почти 3 года назад

Security update for curl

EPSS: Низкий
redos логотип

ROS-20230407-01

почти 3 года назад

Множественные уязвимости libcurl

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2228-1

больше 2 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2226-1

больше 2 лет назад

Security update for curl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-27538

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-27538

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-27538

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 5.5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-27538

An authentication bypass vulnerability exists in libcurl prior to v8.0 ...

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-cgj3-cvg6-pcvh

An authentication bypass vulnerability exists in libcurl v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-02103

Уязвимость библиотеки libcurl, связанная с обходом процедуры аутентификации, позволяющая нарушителю повторно использовать неподходящее соединение

CVSS3: 6.5
0%
Низкий
почти 3 года назад
redos логотип
ROS-20230407-21

Множественные уязвимости curl

CVSS3: 5.9
почти 3 года назад
oracle-oval логотип
ELSA-2023-6679

ELSA-2023-6679: curl security update (MODERATE)

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:1582-1

Security update for curl

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:0865-1

Security update for curl

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:1711-1

Security update for curl

почти 3 года назад
redos логотип
ROS-20230407-01

Множественные уязвимости libcurl

CVSS3: 5.9
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:2228-1

Security update for curl

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2226-1

Security update for curl

больше 2 лет назад

Уязвимостей на страницу