endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

CVE-2022-22576 | curl (CWE-287) #11

Open mgulter opened 2 years ago

mgulter commented 2 years ago

A high severity vulnerability has been discovered in your project.

Project Name: IssueTest

Scanner Name: trivy

Cwe ID: 287

Cwe Name: Improper Authentication

Cwe Link: https://cwe.mitre.org/data/definitions/287.html

CVE ID: CVE-2022-22576

Target: nginx:latest (debian 11.3)

Packages:

References:

Training(Secure Code Warrior):

Tool Description: An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

Custom Description: test