A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2020-12-14T19:38:26

Updated: 2024-08-04T09:56:28.316Z

Reserved: 2020-01-28T00:00:00

Link: CVE-2020-8284

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-12-14T20:15:13.903

Modified: 2024-04-08T22:50:54.947

Link: CVE-2020-8284

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-12-09T08:00:00Z

Links: CVE-2020-8284 - Bugzilla