CVE-2024-8096

ADVISORY - ubuntu

Summary

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.

EPSS Score: 0.00136 (0.348)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Certificate Validation

ADVISORY - redhat

Improper Certificate Validation


Ubuntu

CREATED

UPDATED

ADVISORY IDCVE-2024-8096
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium
PackageTypeOS NameOS VersionAffected RangesFix Versions
ubuntu/curldebubuntu22.04<7.81.0-1ubuntu1.187.81.0-1ubuntu1.18
ubuntu/curldebubuntu24.04<8.5.0-2ubuntu10.48.5.0-2ubuntu10.4
ubuntu/curldebubuntu20.04<7.68.0-1ubuntu2.247.68.0-1ubuntu2.24
ubuntu/curldebubuntu24.10<8.9.1-2ubuntu28.9.1-2ubuntu2
ubuntu/curldebubuntu25.04<8.9.1-2ubuntu28.9.1-2ubuntu2
ubuntu/curldebubuntu14.04>=0Not yet available

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

ADVISORY IDCVE-2024-8096
EXPLOITABILITY SCORE

3.9

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.5medium

Alpine

CREATED

UPDATED

ADVISORY IDCVE-2024-8096
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Debian

CREATED

UPDATED

ADVISORY IDCVE-2024-8096
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Red Hat

CREATED

UPDATED

ADVISORY IDCVE-2024-8096
EXPLOITABILITY SCORE

3.9

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.5medium

Chainguard

CREATED

UPDATED

ADVISORY ID

CGA-g55g-qx76-5fjj

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Photon

CREATED

UPDATED

ADVISORY ID

CVE-2024-8096

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

6.5medium