Back

MEDIUM

Usage of disabled protocol

Published Mar 27, 2024

Description

When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.se The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.

Affected products

Remediation

Red Hat statement

The curl package as shipped in Red Hat Enterprise Linux 6, 7, 8, 9, and RHSCL is not affected by this vulnerability because the vulnerable code was introduced in a newer version of curl.

Metrics

Weaknesses (2)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner curl
Published Mar 27, 2024
Updated Feb 13, 2025
Reserved Feb 29, 2024
CISA Vulnrichment
Updated Apr 25, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 27, 2024