Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j5mq-cppw-g9w7

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.

curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.

EPSS

Процентиль: 96%
0.15063
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.

CVSS3: 4.8
redhat
около 10 лет назад

curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.

CVSS3: 7.5
nvd
почти 10 лет назад

curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.

CVSS3: 7.5
debian
почти 10 лет назад

curl and libcurl before 7.50.1 do not prevent TLS session resumption w ...

suse-cvrf
почти 10 лет назад

Security update for curl

EPSS

Процентиль: 96%
0.15063
Средний

7.5 High

CVSS3