cve/2024/CVE-2024-0853.md
2024-05-25 21:48:12 +02:00

851 B

CVE-2024-0853

Description

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (OCSP stapling) test failed. A subsequent transfer tothe same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.

POC

Reference

No PoCs from references.

Github