CVE-2023-27535: Debian Linux
Medium severity, CVSS 5.9. EPSS: 1.6% chance of exploitation in the next 30 days.
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.
Affected products
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 36 only
- Haxx Libcurl: from 7.13.0, up to and including 7.88.1
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp h300s Firmware: affected versions not specified
- Netapp h410s Firmware: affected versions not specified
- Netapp h500s Firmware: affected versions not specified
- Netapp h700s Firmware: affected versions not specified
- Netapp Ontap 9: affected versions not specified
- Splunk Universal Forwarder: from 8.2.0, before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6); version 9.1.0 only
Published 2023-03-30. Last modified 2026-06-17.