Логотип exploitDog
bind:CVE-2024-2379
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-2379

Количество 7

Количество 7

ubuntu логотип

CVE-2024-2379

почти 2 года назад

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2024-2379

почти 2 года назад

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-2379

почти 2 года назад

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

CVSS3: 6.3
EPSS: Низкий
msrc логотип

CVE-2024-2379

больше 1 года назад

EPSS: Низкий
debian логотип

CVE-2024-2379

почти 2 года назад

libcurl skips the certificate verification for a QUIC connection under ...

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-wr4c-gwg7-p734

почти 2 года назад

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

CVSS3: 6.3
EPSS: Низкий
fstec логотип

BDU:2024-02721

почти 2 года назад

Уязвимость функции curl_wssl_init_ctx компонента vquic-tls.c утилиты командной строки cURL, позволяющая нарушителю игнорировать любые проблемы с сертификатами

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-2379

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-2379

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-2379

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
msrc логотип
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-2379

libcurl skips the certificate verification for a QUIC connection under ...

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-wr4c-gwg7-p734

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-02721

Уязвимость функции curl_wssl_init_ctx компонента vquic-tls.c утилиты командной строки cURL, позволяющая нарушителю игнорировать любые проблемы с сертификатами

CVSS3: 5.6
0%
Низкий
почти 2 года назад

Уязвимостей на страницу