CVE-2024-0853Improper Certificate Validation in Curl

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 63.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 3
Latest updateJul 15

Description

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

Alpinehaxx/curl< 8.6.0-r0+6
Debianhaxx/curl< 8.6.0-1+1
CVEListV5curl/curl8.5.08.5.0
NVDhaxx/curl8.5.0

🔴Vulnerability Details

4
OSV
CVE-2024-0853: curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed2024-02-03
GHSA
GHSA-697h-9h25-w4fm: curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed2024-02-03
OSV
CVE-2024-0853: curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed2024-02-03
CVEList
OCSP verification bypass with TLS session reuse2024-02-03

📋Vendor Advisories

5
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (curl) — CVE-2024-08532024-07-15
Oracle
Oracle Oracle MySQL Risk Matrix: Cluster: General (curl) — CVE-2024-08532024-04-15
Microsoft
OCSP verification bypass with TLS session reuse2024-02-13
Red Hat
curl: OCSP verification bypass with TLS session reuse2024-01-31
Debian
CVE-2024-0853: curl - curl inadvertently kept the SSL session ID for connections in its cache even whe...2024

💬Community

2
HackerOne
CVE-2024-0853: OCSP verification bypass with TLS session reuse2024-03-27
HackerOne
CVE-2024-0853: OCSP verification bypass with TLS session reuse2024-01-31
CVE-2024-0853 — Improper Certificate Validation in Curl | cvebase