Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39874
HistoryMar 21, 2023 - 12:27 a.m.

Authentication Bypass

2023-03-2100:27:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
32
authentication bypass
curl
ftp
configuration match

EPSS

0.002

Percentile

62.4%

curl is vulnerable to Authentication Bypass. The library would reuse a previously created FTP connection even when one or more options had been changed, leading to wrong credentials. Several FTP settings were left out from configuration match checks, making them easily match.