• Gabriel N@infosec.exchange
    link
    fedilink
    arrow-up
    1
    ·
    5 days ago

    @harrysintonen@infosec.exchange nice find, I don’t know how curl defines a vulnerability, but it definitely should have more warnings and preferably fail closed, although that might break quite a few systems which depend on this insecure behaviour

  • Dubiousx99@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    7 days ago

    This is a good post and article. It actually contains enough information to make an assessment about how this vulnerability equates to risk in our environments. I completely agree with the author that curl requests should fail if they can’t perform validation as defined being the default behavior.