Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ppfq-jg49-mqj4

Опубликовано: 28 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

EPSS

Процентиль: 3%
0.00018
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
22 дня назад

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

CVSS3: 6.5
redhat
22 дня назад

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

CVSS3: 6.5
nvd
22 дня назад

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

CVSS3: 6.5
debian
22 дня назад

libcurl accidentally skips the certificate verification for QUIC conne ...

EPSS

Процентиль: 3%
0.00018
Низкий

6.5 Medium

CVSS3