CVE Database
/

CVE-2020-8284

Back to search

CVE-2020-8284

Published: Dec 14, 2020

Modified: Apr 16, 2026

PUBLISHED

Description

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

VendorProductVersions

n/a

https://github.com/curl/curl

affected
7.73.0 and earlier

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now