发布时间: 2022年5月18日
修改时间: 2024年10月31日
This security flaw in curl allows to reuse an OAUTH2 authenticated connection without properly ensuring that the connection is authenticated with the same credentials set by this transport, this issue can lead to authentication bypasses, either by mistake or by malicious actors.
NVD | openEuler | |
---|---|---|
Confidentiality | High | Low |
Attack Vector | Network | Network |
CVSS评分 | 8.1 | 4.6 |
Attack Complexity | Low | Low |
Privileges Required | Low | Low |
Scope | Unchanged | Unchanged |
Integrity | High | Low |
User Interaction | None | Required |
Availability | None | None |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2022-1530 | curl security update | 2022年5月18日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | curl | Fixed |
KY3.4-5 | curl | Fixed |
KY3.5.1 | curl | Fixed |