Lucene search

K
hackeroneNyymiH1:1614332
HistoryJun 27, 2022 - 7:11 a.m.

Internet Bug Bounty: CVE-2022-32208: FTP-KRB bad message verification

2022-06-2707:11:13
nyymi
hackerone.com
$480
78

0.003 Low

EPSS

Percentile

69.5%

When curl does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.

Impact

Loss of integrity of FTP-KRB transfers