CVE-2020-8231 describes a high-severity vulnerability in libcurl versions 7.29.0 through 7.71.1, affecting products from vendors like Debian, Oracle, Siemens, and Splunk. This flaw, categorized as a dangling pointer (CWE-416), allows libcurl to use an incorrect connection when transmitting data, potentially leading to information disclosure (CVSS 7.5, C:H). The vulnerability is network-exploitable with low attack complexity and requires no user interaction or privileges. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.29.0, <= 7.71.1CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:* | ||
< 1.0.1.1CPE matchmatch criteria | cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
1.14.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:* | ||
>= 8.2.0, < 8.2.12CPE matchmatch criteria | cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
August Third Party Package Updates in Splunk Universal Forwarder
Aug 30, 2023Due to use of a dangling pointer libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.
Dec 8, 2020curl: Expired pointer dereference via multi API with CURLOPT_CONNECT_ONLY option set
Aug 19, 2020wrong connect-only connection
Aug 19, 2020