libcurl is vulnerable to Authentication Bypass
55
Medium Risk
Negotiate authentication with empty credentials means the ambient user, whose identity lives outside libcurl. Reusing the connection for a later request still sends that request on the connection authenticated as the earlier ambient user, even when the ambient user has changed, so one user's request runs with another user's authenticated session. The fix stops that reuse for blank Negotiate credentials.
You are affected if you are using a version that falls within the vulnerable range and you reuse connections for Negotiate authentication with empty credentials.
libcurl is vulnerable to Authentication Bypass in versions 7.64.1 - 8.21.0.
Upgrade the libcurl and/or the curl.curl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.