Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-27536

An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.5%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2023-27536
  • Haxx » Libcurl » Version: 7.22.0
    cpe:2.3:a:haxx:libcurl:7.22.0
  • Haxx » Libcurl » Version: 7.23.0
    cpe:2.3:a:haxx:libcurl:7.23.0
  • Haxx » Libcurl » Version: 7.23.1
    cpe:2.3:a:haxx:libcurl:7.23.1
  • Haxx » Libcurl » Version: 7.24.0
    cpe:2.3:a:haxx:libcurl:7.24.0
  • Haxx » Libcurl » Version: 7.25.0
    cpe:2.3:a:haxx:libcurl:7.25.0
  • Haxx » Libcurl » Version: 7.26.0
    cpe:2.3:a:haxx:libcurl:7.26.0
  • Haxx » Libcurl » Version: 7.27.0
    cpe:2.3:a:haxx:libcurl:7.27.0
  • Haxx » Libcurl » Version: 7.28.0
    cpe:2.3:a:haxx:libcurl:7.28.0
  • Haxx » Libcurl » Version: 7.28.1
    cpe:2.3:a:haxx:libcurl:7.28.1
  • Haxx » Libcurl » Version: 7.29.0
    cpe:2.3:a:haxx:libcurl:7.29.0
  • Haxx » Libcurl » Version: 7.30.0
    cpe:2.3:a:haxx:libcurl:7.30.0
  • Haxx » Libcurl » Version: 7.31.0
    cpe:2.3:a:haxx:libcurl:7.31.0
  • Haxx » Libcurl » Version: 7.32.0
    cpe:2.3:a:haxx:libcurl:7.32.0
  • Haxx » Libcurl » Version: 7.33.0
    cpe:2.3:a:haxx:libcurl:7.33.0
  • Haxx » Libcurl » Version: 7.34.0
    cpe:2.3:a:haxx:libcurl:7.34.0
  • Haxx » Libcurl » Version: 7.35.0
    cpe:2.3:a:haxx:libcurl:7.35.0
  • Haxx » Libcurl » Version: 7.36.0
    cpe:2.3:a:haxx:libcurl:7.36.0
  • Haxx » Libcurl » Version: 7.37.0
    cpe:2.3:a:haxx:libcurl:7.37.0
  • Haxx » Libcurl » Version: 7.37.1
    cpe:2.3:a:haxx:libcurl:7.37.1
  • Haxx » Libcurl » Version: 7.38.0
    cpe:2.3:a:haxx:libcurl:7.38.0
  • Haxx » Libcurl » Version: 7.39
    cpe:2.3:a:haxx:libcurl:7.39
  • Haxx » Libcurl » Version: 7.39.0
    cpe:2.3:a:haxx:libcurl:7.39.0
  • Haxx » Libcurl » Version: 7.40.0
    cpe:2.3:a:haxx:libcurl:7.40.0
  • Haxx » Libcurl » Version: 7.41.0
    cpe:2.3:a:haxx:libcurl:7.41.0
  • Haxx » Libcurl » Version: 7.42
    cpe:2.3:a:haxx:libcurl:7.42
  • Haxx » Libcurl » Version: 7.42.0
    cpe:2.3:a:haxx:libcurl:7.42.0
  • Haxx » Libcurl » Version: 7.42.1
    cpe:2.3:a:haxx:libcurl:7.42.1
  • Haxx » Libcurl » Version: 7.43.0
    cpe:2.3:a:haxx:libcurl:7.43.0
  • Haxx » Libcurl » Version: 7.44.0
    cpe:2.3:a:haxx:libcurl:7.44.0
  • Haxx » Libcurl » Version: 7.45.0
    cpe:2.3:a:haxx:libcurl:7.45.0
  • Haxx » Libcurl » Version: 7.46.0
    cpe:2.3:a:haxx:libcurl:7.46.0
  • Haxx » Libcurl » Version: 7.47.0
    cpe:2.3:a:haxx:libcurl:7.47.0
  • Haxx » Libcurl » Version: 7.47.1
    cpe:2.3:a:haxx:libcurl:7.47.1
  • Haxx » Libcurl » Version: 7.48.0
    cpe:2.3:a:haxx:libcurl:7.48.0
  • Haxx » Libcurl » Version: 7.49.0
    cpe:2.3:a:haxx:libcurl:7.49.0
  • Haxx » Libcurl » Version: 7.49.1
    cpe:2.3:a:haxx:libcurl:7.49.1
  • Haxx » Libcurl » Version: 7.50.0
    cpe:2.3:a:haxx:libcurl:7.50.0
  • Haxx » Libcurl » Version: 7.50.1
    cpe:2.3:a:haxx:libcurl:7.50.1
  • Haxx » Libcurl » Version: 7.50.2
    cpe:2.3:a:haxx:libcurl:7.50.2
  • Haxx » Libcurl » Version: 7.50.3
    cpe:2.3:a:haxx:libcurl:7.50.3
  • Haxx » Libcurl » Version: 7.51.0
    cpe:2.3:a:haxx:libcurl:7.51.0
  • Haxx » Libcurl » Version: 7.52.0
    cpe:2.3:a:haxx:libcurl:7.52.0
  • Haxx » Libcurl » Version: 7.52.1
    cpe:2.3:a:haxx:libcurl:7.52.1
  • Haxx » Libcurl » Version: 7.53.0
    cpe:2.3:a:haxx:libcurl:7.53.0
  • Haxx » Libcurl » Version: 7.53.1
    cpe:2.3:a:haxx:libcurl:7.53.1
  • Haxx » Libcurl » Version: 7.54.0
    cpe:2.3:a:haxx:libcurl:7.54.0
  • Haxx » Libcurl » Version: 7.54.1
    cpe:2.3:a:haxx:libcurl:7.54.1
  • Haxx » Libcurl » Version: 7.55.0
    cpe:2.3:a:haxx:libcurl:7.55.0
  • Haxx » Libcurl » Version: 7.55.1
    cpe:2.3:a:haxx:libcurl:7.55.1
  • Haxx » Libcurl » Version: 7.56.0
    cpe:2.3:a:haxx:libcurl:7.56.0
  • Haxx » Libcurl » Version: 7.56.1
    cpe:2.3:a:haxx:libcurl:7.56.1
  • Haxx » Libcurl » Version: 7.57.0
    cpe:2.3:a:haxx:libcurl:7.57.0
  • Haxx » Libcurl » Version: 7.58.0
    cpe:2.3:a:haxx:libcurl:7.58.0
  • Haxx » Libcurl » Version: 7.59.0
    cpe:2.3:a:haxx:libcurl:7.59.0
  • Haxx » Libcurl » Version: 7.60.0
    cpe:2.3:a:haxx:libcurl:7.60.0
  • Haxx » Libcurl » Version: 7.61.0
    cpe:2.3:a:haxx:libcurl:7.61.0
  • Haxx » Libcurl » Version: 7.61.1
    cpe:2.3:a:haxx:libcurl:7.61.1
  • Haxx » Libcurl » Version: 7.62.0
    cpe:2.3:a:haxx:libcurl:7.62.0
  • Haxx » Libcurl » Version: 7.63.0
    cpe:2.3:a:haxx:libcurl:7.63.0
  • Haxx » Libcurl » Version: 7.64.0
    cpe:2.3:a:haxx:libcurl:7.64.0
  • Haxx » Libcurl » Version: 7.64.1
    cpe:2.3:a:haxx:libcurl:7.64.1
  • Haxx » Libcurl » Version: 7.65.0
    cpe:2.3:a:haxx:libcurl:7.65.0
  • Haxx » Libcurl » Version: 7.65.1
    cpe:2.3:a:haxx:libcurl:7.65.1
  • Haxx » Libcurl » Version: 7.65.2
    cpe:2.3:a:haxx:libcurl:7.65.2
  • Haxx » Libcurl » Version: 7.65.3
    cpe:2.3:a:haxx:libcurl:7.65.3
  • Haxx » Libcurl » Version: 7.66.0
    cpe:2.3:a:haxx:libcurl:7.66.0
  • Haxx » Libcurl » Version: 7.67.0
    cpe:2.3:a:haxx:libcurl:7.67.0
  • Haxx » Libcurl » Version: 7.68.0
    cpe:2.3:a:haxx:libcurl:7.68.0
  • Haxx » Libcurl » Version: 7.69.0
    cpe:2.3:a:haxx:libcurl:7.69.0
  • Haxx » Libcurl » Version: 7.69.1
    cpe:2.3:a:haxx:libcurl:7.69.1
  • Haxx » Libcurl » Version: 7.70.0
    cpe:2.3:a:haxx:libcurl:7.70.0
  • Haxx » Libcurl » Version: 7.71.0
    cpe:2.3:a:haxx:libcurl:7.71.0
  • Haxx » Libcurl » Version: 7.71.1
    cpe:2.3:a:haxx:libcurl:7.71.1
  • Haxx » Libcurl » Version: 7.72.0
    cpe:2.3:a:haxx:libcurl:7.72.0
  • Haxx » Libcurl » Version: 7.73.0
    cpe:2.3:a:haxx:libcurl:7.73.0
  • Haxx » Libcurl » Version: 7.74.0
    cpe:2.3:a:haxx:libcurl:7.74.0
  • Haxx » Libcurl » Version: 7.75.0
    cpe:2.3:a:haxx:libcurl:7.75.0
  • Haxx » Libcurl » Version: 7.77.0
    cpe:2.3:a:haxx:libcurl:7.77.0
  • Haxx » Libcurl » Version: 7.78.0
    cpe:2.3:a:haxx:libcurl:7.78.0
  • Haxx » Libcurl » Version: 7.79.0
    cpe:2.3:a:haxx:libcurl:7.79.0
  • Haxx » Libcurl » Version: 7.79.1
    cpe:2.3:a:haxx:libcurl:7.79.1
  • Haxx » Libcurl » Version: 7.80.0
    cpe:2.3:a:haxx:libcurl:7.80.0
  • Haxx » Libcurl » Version: 7.81.0
    cpe:2.3:a:haxx:libcurl:7.81.0
  • Haxx » Libcurl » Version: 7.82.0
    cpe:2.3:a:haxx:libcurl:7.82.0
  • Haxx » Libcurl » Version: 7.83.0
    cpe:2.3:a:haxx:libcurl:7.83.0
  • Haxx » Libcurl » Version: 7.83.1
    cpe:2.3:a:haxx:libcurl:7.83.1
  • Haxx » Libcurl » Version: 7.84.0
    cpe:2.3:a:haxx:libcurl:7.84.0
  • Haxx » Libcurl » Version: 7.85.0
    cpe:2.3:a:haxx:libcurl:7.85.0
  • Haxx » Libcurl » Version: 7.86.0
    cpe:2.3:a:haxx:libcurl:7.86.0
  • Haxx » Libcurl » Version: 7.87.0
    cpe:2.3:a:haxx:libcurl:7.87.0
  • Haxx » Libcurl » Version: 7.88.0
    cpe:2.3:a:haxx:libcurl:7.88.0
  • Haxx » Libcurl » Version: 7.88.1
    cpe:2.3:a:haxx:libcurl:7.88.1
  • Netapp » Active Iq Unified Manager » Version: N/A
    cpe:2.3:a:netapp:active_iq_unified_manager:-
  • Netapp » Ontap » Version: 9
    cpe:2.3:a:netapp:ontap:9
  • Splunk » Universal Forwarder » Version: 8.2.0
    cpe:2.3:a:splunk:universal_forwarder:8.2.0
  • Splunk » Universal Forwarder » Version: 8.2.10
    cpe:2.3:a:splunk:universal_forwarder:8.2.10
  • Splunk » Universal Forwarder » Version: 8.2.11
    cpe:2.3:a:splunk:universal_forwarder:8.2.11
  • Splunk » Universal Forwarder » Version: 8.2.6
    cpe:2.3:a:splunk:universal_forwarder:8.2.6
  • Splunk » Universal Forwarder » Version: 8.2.7
    cpe:2.3:a:splunk:universal_forwarder:8.2.7
  • Splunk » Universal Forwarder » Version: 8.2.8
    cpe:2.3:a:splunk:universal_forwarder:8.2.8
  • Splunk » Universal Forwarder » Version: 8.2.9
    cpe:2.3:a:splunk:universal_forwarder:8.2.9
  • Splunk » Universal Forwarder » Version: 9.0.0
    cpe:2.3:a:splunk:universal_forwarder:9.0.0
  • Splunk » Universal Forwarder » Version: 9.0.1
    cpe:2.3:a:splunk:universal_forwarder:9.0.1
  • Splunk » Universal Forwarder » Version: 9.0.2
    cpe:2.3:a:splunk:universal_forwarder:9.0.2
  • Splunk » Universal Forwarder » Version: 9.0.3
    cpe:2.3:a:splunk:universal_forwarder:9.0.3
  • Splunk » Universal Forwarder » Version: 9.0.4
    cpe:2.3:a:splunk:universal_forwarder:9.0.4
  • Splunk » Universal Forwarder » Version: 9.0.5
    cpe:2.3:a:splunk:universal_forwarder:9.0.5
  • Splunk » Universal Forwarder » Version: 9.1.0
    cpe:2.3:a:splunk:universal_forwarder:9.1.0
  • Netapp » H300s » Version: N/A
    cpe:2.3:h:netapp:h300s:-
  • Netapp » H410s » Version: N/A
    cpe:2.3:h:netapp:h410s:-
  • Netapp » H500s » Version: N/A
    cpe:2.3:h:netapp:h500s:-
  • Netapp » H700s » Version: N/A
    cpe:2.3:h:netapp:h700s:-
  • Debian » Debian Linux » Version: 10.0
    cpe:2.3:o:debian:debian_linux:10.0
  • Fedoraproject » Fedora » Version: 36
    cpe:2.3:o:fedoraproject:fedora:36
  • Netapp » H300s Firmware » Version: N/A
    cpe:2.3:o:netapp:h300s_firmware:-
  • Netapp » H410s Firmware » Version: N/A
    cpe:2.3:o:netapp:h410s_firmware:-
  • Netapp » H500s Firmware » Version: N/A
    cpe:2.3:o:netapp:h500s_firmware:-
  • Netapp » H700s Firmware » Version: N/A
    cpe:2.3:o:netapp:h700s_firmware:-


Contact Us

Shodan ® - All rights reserved