Description
The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.
Remediation
References
Related Vulnerabilities
XWiki Missing Authentication for Critical Function Vulnerability (CVE-2022-24820)
WordPress 4.2.x Same Origin Method Execution (SOME) Vulnerability (4.2 - 4.2.7)
Atlassian Jira Missing Authentication for Critical Function Vulnerability (CVE-2019-8449)
Drupal Incorrect Default Permissions Vulnerability (CVE-2020-13667)