Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23807
HistoryApr 10, 2020 - 12:36 a.m.

Arbitrary Code Execution

2020-04-1000:36:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.008 Low

EPSS

Percentile

81.1%

curl is vulnerable to arbitrary code execution. A flaw in libcurl where it would not differentiate between different target URLs when handling automatic redirects. This caused libcurl to follow any new URL that it understood, including the “file://” URL type. This could allow a remote server to force a local libcurl-using application to read a local file instead of the remote one, possibly exposing local files that were not meant to be exposed.

References