Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8286

Опубликовано: 09 дек. 2020
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

Libcurl offers "OCSP stapling" via the CURLOPT_SSL_VERIFYSTATUS option. When set, libcurl verifies the OCSP response that a server responds with as part of the TLS handshake. It then aborts the TLS negotiation if something is wrong with the response. The same feature can be enabled with --cert-status using the curl tool. As part of the OCSP response verification, a client should verify that the response is indeed set out for the correct certificate. This step was not performed by libcurl when built or told to use OpenSSL as TLS backend.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 2.1 on Red Hat Enterprise Linuxrh-dotnet21-curlNot affected
.NET Core 3.1 on Red Hat Enterprise Linuxrh-dotnet31-curlNot affected
Red Hat Ceph Storage 2curlOut of support scope
Red Hat Enterprise Linux 5curlNot affected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected
Red Hat Software Collectionshttpd24-curlWill not fix
JBoss Core Services Apache HTTP Server 2.4.37 SP8jbcs-httpd24-curlFixedRHSA-2021:247117.06.2021
JBoss Core Services for RHEL 8jbcs-httpd24FixedRHSA-2021:247217.06.2021
JBoss Core Services for RHEL 8jbcs-httpd24-aprFixedRHSA-2021:247217.06.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295

EPSS

Процентиль: 51%
0.00283
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

CVSS3: 7.5
nvd
около 5 лет назад

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

CVSS3: 7.5
msrc
около 5 лет назад

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

CVSS3: 7.5
debian
около 5 лет назад

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for cert ...

CVSS3: 7.5
github
больше 3 лет назад

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

EPSS

Процентиль: 51%
0.00283
Низкий

7.4 High

CVSS3