6.5

CVE-2024-8096

Exploit

OCSP stapling bypass with GnuTLS

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine.  If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haxx ≫ Curl Version >= 7.41.0 < 8.10.0
Debian ≫ Debian Linux Version 11.0
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Ontap Tools Version 10 SwPlatform vmware_vsphere
Netapp ≫ Bootstrap Os Version -
   Netapp ≫ Hci Compute Node Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.73% 0.494
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://curl.se/docs/CVE-2024-8096.html
Vendor Advisory
https://curl.se/docs/CVE-2024-8096.json
Vendor Advisory
https://hackerone.com/reports/2669852
Third Party Advisory
Exploit
Issue Tracking
http://www.openwall.com/lists/oss-security/2024/09/11/1
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2024/11/msg00008.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20241011-0005/
Third Party Advisory