A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/27xxx/CVE-2023-27534.json",
"cwe_ids": [
"CWE-22"
],
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "Fixed in 8.0.0"
}
],
"source": "AFFECTED_FIELD"
}
],
"cna_assigner": "hackerone"
}