CVE-2020-8284

LOW

curl < 7.73.0 - Exposure of Sensitive Information via FTP PASV Response

Title source: llm
STIX 2.1

Description

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

References (16)

Core 16
Core References
Permissions Required x_refsource_misc
https://hackerone.com/reports/1040166
Vendor Advisory x_refsource_misc
https://curl.se/docs/CVE-2020-8284.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202012-14
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4881
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuApr2021.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210122-0007/
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212325
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212326
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212327
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html
Patch, Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf

Scores

CVSS v3 3.7
EPSS 0.0010
EPSS Percentile 27.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (28)
None/https://github.com/curl/curl 7.73.0 and earlier
apple/mac_os_x 10.14.6 security_update_2019-001 (17 CPE variants)
apple/mac_os_x 10.15.7 (7 CPE variants)
apple/mac_os_x 10.14.0 - 10.14.6
apple/macos 11.0.1
apple/macos 11.1
apple/macos 11.2
debian/debian_linux 9.0
debian/debian_linux 10.0
fedoraproject/fedora 32
... and 18 more
Published Dec 14, 2020
Tracked Since Feb 18, 2026