CVE-2020-8284: Infoleak
A malicious server can use the PASV response to trick curl into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions. If curl operates on a URL provided by a user (which by all means is an unwise setup), a user can exploit that and pass in a URL to a malicious FTP server instance without needing any server breach to perform the attack.
Other sources
A malicious server can use the PASV response to trick curl into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions. If curl operates on a URL provided by a user, a user can exploit that and pass in a URL to a malicious FTP server instance without needing any server breach to perform the attack.
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
cURL libcurl could allow a remote attacker to obtain sensitive information, caused by improper validation of FTP PASV responses. By persuading a victim to connect a specially-crafted server, an attacker could exploit this vulnerability to obtain sensitive information about services, and use this information to launch further attacks against the affected system.
— IBM
curl. This issue was addressed with improved checks.
Credit
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-1853
- CVE-2021-1849
- CVE-2021-1867
- CVE-2021-1810
- CVE-2021-1808
- CVE-2021-1857
- CVE-2021-30752
- CVE-2021-30664
- CVE-2021-1846
- CVE-2021-1809
- CVE-2021-30659
- CVE-2021-1847
- CVE-2021-1811
- CVE-2020-8284
- CVE-2020-8286
- CVE-2020-8285
- CVE-2021-1784
- CVE-2021-1872
- CVE-2021-1881
- CVE-2021-1882
- CVE-2021-1813
- CVE-2021-1883
- CVE-2021-1884
- CVE-2021-1880
- CVE-2021-30653
- CVE-2021-1814
- CVE-2021-1843
- CVE-2021-1885
- CVE-2021-1858
- CVE-2021-30743
- CVE-2021-30658
- CVE-2021-1841
- CVE-2021-1834
- CVE-2021-1860
- CVE-2021-1840
- CVE-2021-1851
- CVE-2021-1832
- CVE-2021-30660
- CVE-2021-30652
- CVE-2021-1875
- CVE-2021-1824
- CVE-2021-1859
- CVE-2021-1876
- CVE-2021-1815
- CVE-2021-1739
- CVE-2021-1740
- CVE-2021-1861
- CVE-2021-1855
- CVE-2021-1868
- CVE-2021-30750
- CVE-2021-1878
- CVE-2021-30657
- CVE-2021-30856
- CVE-2020-8037
- CVE-2021-1839
- CVE-2021-1825
- CVE-2021-1817
- CVE-2021-1826
- CVE-2021-1820
- CVE-2021-30661
- CVE-2020-7463
- CVE-2021-1828
- CVE-2021-1829
- CVE-2021-30655
- CVE-2021-1770
- CVE-2021-1873
- CVE-2021-1797
- CVE-2020-27942
- CVE-2020-3838
- CVE-2021-1805
- CVE-2021-1806
Frequently Asked Questions
What is CVE-2020-8284?
CVE-2020-8284 is a vulnerability that allows a malicious server to trick curl into connecting back to a given IP address and port, potentially extracting information about private services and performing port scanning.
What is the severity of CVE-2020-8284?
The severity of CVE-2020-8284 is medium with a CVSS score of 3.1.
Which software versions are affected by CVE-2020-8284?
The Red Hat curl package version up to exclusive 7.74.0, and other related packages like jbcs-httpd24, jbcs-httpd24-apr, jbcs-httpd24-apr-util, jbcs-httpd24-brotli, jbcs-httpd24-curl, jbcs-httpd24-httpd, jbcs-httpd24-jansson, jbcs-httpd24-nghttp2, jbcs-httpd24-openssl, jbcs-httpd24-openssl-chil, jbcs-httpd24-openssl-pkcs11, curl version up to exclusive 7.61.1-18.el8, Apple Catalina, Apple Mojave, and Apple macOS Big Sur versions up to exclusive 11.3 are affected by CVE-2020-8284.
How can I fix CVE-2020-8284?
To fix CVE-2020-8284, update the affected software to the recommended versions: curl version 7.74.0 or later, or apply the necessary security updates provided by the software vendor.
Where can I find more information about CVE-2020-8284?
You can find more information about CVE-2020-8284 on the following references: [link 1](https://support.apple.com/en-us/HT212326), [link 2](https://support.apple.com/en-us/HT212327), [link 3](https://support.apple.com/en-us/HT212325).