Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-0853

Опубликовано: 03 фев. 2024
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 5.3

Описание

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (OCSP stapling) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

released

8.5.0-2ubuntu2
esm-infra-legacy/trusty

not-affected

esm-infra-legacy/xenial

not-affected

esm-infra/bionic

not-affected

esm-infra/focal

not-affected

esm-infra/xenial

not-affected

focal

not-affected

jammy

not-affected

lunar

not-affected

Показывать по

EPSS

Процентиль: 63%
0.01102
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.8
redhat
больше 2 лет назад

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.

CVSS3: 5.3
nvd
больше 2 лет назад

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.

CVSS3: 5.3
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 5.3
debian
больше 2 лет назад

curl inadvertently kept the SSL session ID for connections in its cach ...

CVSS3: 5.3
github
больше 2 лет назад

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.

EPSS

Процентиль: 63%
0.01102
Низкий

5.3 Medium

CVSS3