JLSEC-2025-31
Dashboard / Vulnerabilities / JLSEC-2025-31
Summary: An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature...
Details: An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as `CURLOPT_FTP_ACCOUNT`, `CURLOPT_FTP_ALTERNATIVE_TO_USER`, `CURLOPT_FTP_SSL_CCC`, and `CURLOPT_USE_SSL` were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.
References: https://hackerone.com/reports/1892780, https://lists.debian.org/debian-lts-announce/2023/04/msg00025.html, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/, https://security.gentoo.org/glsa/202310-12, https://security.netapp.com/advisory/ntap-20230420-0010/
Affected packages
Package
Name: CURL_jll
Purl: pkg:julia/CURL_jll?uuid=b21e61f3-bafc-59ac-ab14-4c5c62d6588d
Affected ranges
Type: SEMVER
Events:
