CVE Vulnerabilities

CVE-2022-32208

Published: Jul 07, 2022 | Modified: May 05, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.

Affected Software

NameVendorStart VersionEnd Version
CurlHaxx7.16.4 (including)7.84.0 (excluding)
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-curl-0:7.86.0-2.el8jbcs*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-curl-0:7.86.0-2.el7jbcs*
Red Hat Enterprise Linux 8RedHatcurl-0:7.61.1-22.el8_6.4*
Red Hat Enterprise Linux 9RedHatcurl-0:7.76.1-14.el9_0.5*
Red Hat Enterprise Linux 9RedHatcurl-0:7.76.1-14.el9_0.5*
Text-Only JBCSRedHatjbcs-httpd24-curl*
CurlUbuntubionic*
CurlUbuntudevel*
CurlUbuntuesm-infra-legacy/trusty*
CurlUbuntuesm-infra/bionic*
CurlUbuntuesm-infra/focal*
CurlUbuntuesm-infra/xenial*
CurlUbuntufocal*
CurlUbuntuimpish*
CurlUbuntujammy*
CurlUbuntukinetic*
CurlUbuntutrusty/esm*
CurlUbuntuupstream*

References