libcurl is vulnerable to Authentication Bypass
37
Low Risk
LDAP SASL authentication accepts an unfinished handshake as a completed cryptographic check. A peer that can modify the connection can inject a short response and skip the rest of peer validation, so the client accepts the LDAP peer without a finished SASL exchange. The fix requires the handshake to finish before it reports success.
You are affected if you are using a version that falls within the vulnerable range and you use LDAP with SASL authentication.
libcurl is vulnerable to Authentication Bypass in versions 7.82.0 - 8.21.0.
Upgrade the libcurl and/or the curl.curl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.