CVE-2022-32208: FTP-KRB bad message verification

Disclosed: 2022-06-27 20:09:48 By nyymi To ibb
Low
Vulnerability Details
When curl does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client. ## Impact Loss of integrity of FTP-KRB transfers
Actions
View on HackerOne
Report Stats
  • Report ID: 1614332
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report