Lucene search

K
cvelistCurlCVELIST:CVE-2024-0853
HistoryFeb 03, 2024 - 1:35 p.m.

CVE-2024-0853 OCSP verification bypass with TLS session reuse

2024-02-0313:35:25
curl
www.cve.org
2
cve-2024-0853; ocsp verification bypass; tls session reuse; ssl session id; connection cache; verify status.

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.2%

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (OCSP stapling) test failed. A subsequent transfer to
the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.

CNA Affected

[
  {
    "vendor": "curl",
    "product": "curl",
    "versions": [
      {
        "version": "8.5.0",
        "status": "affected",
        "lessThanOrEqual": "8.5.0",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.2%