OCSP stapling bypass with GnuTLS
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.7%
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
nono source reports it
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products
curl · curlReferences
https://curl.se/docs/CVE-2024-8096.htmlhttps://curl.se/docs/CVE-2024-8096.jsonhttps://hackerone.com/reports/2669852https://lists.debian.org/debian-lts-announce/2024/11/msg00008.htmlhttps://security.netapp.com/advisory/ntap-20241011-0005/http://www.openwall.com/lists/oss-security/2024/09/11/1