28 lines
975 B
JSON
Raw Normal View History

{
"id": "CVE-2024-0853",
"sourceIdentifier": "2499f714-1537-4658-8207-48ae4bb9eae9",
"published": "2024-02-03T14:15:50.850",
"lastModified": "2024-02-05T02:09:37.420",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to\nthe same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check."
}
],
"metrics": {},
"references": [
{
"url": "https://curl.se/docs/CVE-2024-0853.html",
"source": "2499f714-1537-4658-8207-48ae4bb9eae9"
},
{
"url": "https://curl.se/docs/CVE-2024-0853.json",
"source": "2499f714-1537-4658-8207-48ae4bb9eae9"
},
{
"url": "https://hackerone.com/reports/2298922",
"source": "2499f714-1537-4658-8207-48ae4bb9eae9"
}
]
}