← Back

CVE-2020-8284

nvd nist
Published: Dec 14, 2020Modified: Jun 17, 2026

JSON object

Loading...
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD

Description

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

Affected (59)

Products: Haxx: Curl · Fedoraproject: Fedora · Debian: Debian Linux · +6 more
Show all products
1 product
Curl
1 product
Fedora
1 product
Debian Linux
5 products
Clustered Data Ontap
Hci Management Node
Hci Storage Node
Solidfire
Hci Bootstrap Os
2 products
Mac Os X
Macos
4 products
Essbase
Peoplesoft Enterprise Peopletools
6 products
M10 1 Firmware
M10 4 Firmware
M10 4s Firmware
M12 1 Firmware
M12 2 Firmware
M12 2s Firmware
1 product
1 product
Universal Forwarder
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 7.73.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Hci Compute Node
All versions
Configuration F
29 vulnerable
Vulnerable SoftwareAffected Versions
Apple
From 10.14.0 to 10.14.6
From 10.15 to 10.15.7
Version 10.14.6 security_update_2019-001
Version 10.14.6 security_update_2019-002
Version 10.14.6 security_update_2019-004
Version 10.14.6 security_update_2019-005
Version 10.14.6 security_update_2019-006
Version 10.14.6 security_update_2019-007
Version 10.14.6 security_update_2020-001
Version 10.14.6 security_update_2020-002
Version 10.14.6 security_update_2020-003
Version 10.14.6 security_update_2020-004
Version 10.14.6 security_update_2020-005
Version 10.14.6 security_update_2020-006
Version 10.14.6 security_update_2020-007
Version 10.14.6 security_update_2021-001
Version 10.14.6 security_update_2021-002
Version 10.14.6 supplemental_update
Version 10.14.6 supplemental_update_2
Version 10.15.7
Version 10.15.7 security_update_2020-001
Version 10.15.7 security_update_2020-005
Version 10.15.7 security_update_2020-007
Version 10.15.7 security_update_2020
Version 10.15.7 security_update_2021-001
Version 10.15.7 supplemental_update
Apple
Version 11.0.1
Version 11.1
Version 11.2
Configuration G
4 vulnerable
Configuration H
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2410
Configuration I
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2410
Configuration J
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2410
Configuration K
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2410
Configuration L
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2410
Configuration M
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2410
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3110
Running on/withPlatform Versions
Fujitsu
M10 1
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3110
Running on/withPlatform Versions
Fujitsu
M10 4
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3110
Running on/withPlatform Versions
Fujitsu
M10 4s
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3110
Running on/withPlatform Versions
Fujitsu
M12 1
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3110
Running on/withPlatform Versions
Fujitsu
M12 2
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3110
Running on/withPlatform Versions
Fujitsu
M12 2s
All versions
Configuration T
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.0.1.1
Configuration U
3 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 8.2.0 to 8.2.12
From 9.0.0 to 9.0.6
Version 9.1.0

References (32)

Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
Vendor Advisory
Source: support@hackerone.com
Permissions Required
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.