#VU62640 Improper Authentication

Published: 2022-04-27

Vulnerability identifier: #VU62640

Vulnerability risk: Medium


CVE-ID: CVE-2022-22576


Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Client/Desktop applications / Other client software

Vendor: curl.haxx.se


The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when re-using OAUTH2 connections for SASL-enabled protocols, such as SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only). libcurl may reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. As a result, a connection that is successfully created and authenticated with a user name + OAUTH2 bearer can subsequently be erroneously reused even for user + [other OAUTH2 bearer], even though that might not even be a valid bearer.

A remote attacker can exploit this vulnerability against applications intended for use in multi-user environments to bypass authentication and gain unauthorized access to victim's accounts.

Install updates from vendor's website.

Vulnerable software versions

cURL: 7.33.0 - 7.82.0


External links

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

Latest bulletins with this vulnerability