cbcvebase.
CVE-2024-0853
published 2024-02-03

CVE-2024-0853: curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the…

PriorityP423medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.19%
40.6th percentile
curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.

Affected

20 ranges
VendorProductVersion rangeFixed in
curlcurl8.5.0 – 8.5.0
debiancurl< curl 8.6.0-1 (forky)curl 8.6.0-1 (forky)
haxxcurl
haxxcurl>= 0 < 8.6.0-r08.6.0-r0
haxxcurl>= 0 < 8.6.0-r08.6.0-r0
haxxcurl>= 0 < 8.6.0-r08.6.0-r0
haxxcurl>= 0 < 8.6.0-r08.6.0-r0
haxxcurl>= 0 < 8.6.0-r08.6.0-r0
haxxcurl>= 0 < 8.6.0-r08.6.0-r0
haxxcurl>= 0 < 8.6.0-r08.6.0-r0
haxxcurl>= 0 < 8.6.0-18.6.0-1
haxxcurl>= 0 < 8.6.0-18.6.0-1
msrcazl3_curl_8.5.0-1_on_azure_linux_3.0
msrcazl3_curl_8.8.0-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_curl_8.5.0-2_on_cbl_mariner_2.0
msrccbl2_curl_8.8.0-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_msrc5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.