When curl does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
{ "issue": "https://hackerone.com/reports/1590071", "CWE": { "id": "CWE-924", "desc": "Improper Enforcement of Message Integrity During Transmission in a Communication Channel" }, "affects": "both", "last_affected": "7.83.1", "URL": "https://curl.se/docs/CVE-2022-32208.json", "award": { "amount": "480", "currency": "USD" }, "severity": "Low", "package": "curl", "www": "https://curl.se/docs/CVE-2022-32208.html" }