When curl does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
{ "CWE": { "id": "CWE-924", "desc": "Improper Enforcement of Message Integrity During Transmission in a Communication Channel" }, "award": { "amount": "480", "currency": "USD" }, "URL": "https://curl.se/docs/CVE-2022-32208.json", "package": "curl", "severity": "Low", "issue": "https://hackerone.com/reports/1590071", "www": "https://curl.se/docs/CVE-2022-32208.html", "last_affected": "7.83.1" }