OCSP verification bypass with TLS session reuse
Published Feb 3, 2024
5.3
MEDIUMCVSS 3.1
EPSS 1.10%
Description
curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.
Affected products
-
Affected
- 8.5.0
No data.
Red Hat Enterprise Linux 6
curl
Not affected
Red Hat Enterprise Linux 7
curl
Not affected
Red Hat Enterprise Linux 8
curl
Not affected
Red Hat Enterprise Linux 9
curl
Not affected
Red Hat JBoss Core Services
jbcs-httpd24-curl
Not affected
Red Hat Software Collections
httpd24-curl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 9 | curl | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-curl | Not affected | n/a |
| Red Hat Software Collections | httpd24-curl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This CVE only affects upstream Curl version 8.5.0. No Red Hat products are affected by this CVE.
References (11)
- https://access.redhat.com/security/cve/CVE-2024-0853 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2262097 Issue Tracking
- https://curl.se/docs/CVE-2024-0853.html Vendor Advisory
- https://curl.se/docs/CVE-2024-0853.json Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-16636 Advisory
- https://hackerone.com/reports/2298922 ExploitIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2024-0853
- https://security.netapp.com/advisory/ntap-20240307-0004/
- https://security.netapp.com/advisory/ntap-20240426-0009/
- https://security.netapp.com/advisory/ntap-20240503-0012/
- https://www.cve.org/CVERecord?id=CVE-2024-0853
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data