Описание
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
Ссылки
- PatchVendor Advisory
- Vendor Advisory
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.30.0 (включая) до 8.21.0 (исключая)
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00309
Низкий
8.1 High
CVSS3
Дефекты
CWE-295
Связанные уязвимости
CVSS3: 8.1
ubuntu
2 месяца назад
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
CVSS3: 8.1
redhat
2 месяца назад
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
CVSS3: 8.1
debian
2 месяца назад
A vulnerability exists where a new transfer that uses STARTTLS to upgr ...
EPSS
Процентиль: 24%
0.00309
Низкий
8.1 High
CVSS3
Дефекты
CWE-295