Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-0853
HistoryFeb 03, 2024 - 2:15 p.m.

Design/Logic Flaw

2024-02-0314:15:00
PRIOn knowledge base
www.prio-n.com
11
design logic flaw
ssl session id
cache
verify status check
nvd

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

24.2%

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (OCSP stapling) test failed. A subsequent transfer to
the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.

CPENameOperatorVersion
curleq8.5.0

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

24.2%