« Volver al listado

CVE-2024-0853

Estado: ModificadaMedia (5.3)—

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-0853",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-0853",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-02-13T19:54:33.332536Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9",
      "affectedData": [
        {
          "vendor": "curl",
          "product": "curl",
          "versions": [
            {
              "status": "affected",
              "version": "8.5.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.5.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-02-03T14:15:50.850",
  "references": [
    {
      "url": "https://curl.se/docs/CVE-2024-0853.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9"
    },
    {
      "url": "https://curl.se/docs/CVE-2024-0853.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9"
    },
    {
      "url": "https://hackerone.com/reports/2298922",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ],
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240307-0004/",
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240426-0009/",
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240503-0012/",
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9"
    },
    {
      "url": "https://curl.se/docs/CVE-2024-0853.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://curl.se/docs/CVE-2024-0853.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://hackerone.com/reports/2298922",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240307-0004/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240426-0009/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240503-0012/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to\nthe same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check."
    },
    {
      "lang": "es",
      "value": "curl inadvertidamente mantuvo el ID de sesión SSL para las conexiones en su caché incluso cuando falló la prueba de verificación del estado (*OCSP stapling*). Una transferencia posterior al mismo nombre de host podría tener éxito si la caché de ID de sesión aún estuviera actualizada, lo que luego omitiría la verificación de estado de verificación."
    }
  ],
  "lastModified": "2026-06-17T06:54:26.133",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:haxx:curl:8.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3F10DBE-EB62-4DCA-A46B-651A39A3502B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "2499f714-1537-4658-8207-48ae4bb9eae9"
}