libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Jun 6, 2024 | Mar 27, 2024 |
| Apple Osx Curl | — | Upgrade macOS to the latest version | Jul 31, 2024 | Mar 27, 2024 |
| Debian | — | Upgrade curl | Jul 27, 2026 | Jul 27, 2026 |
| Gentoo Linux | — | Upgrade net-misc/curl. | Sep 24, 2024 | Mar 27, 2024 |
| Ibm Aix | — | Apply the fix or workaround for curl_advisory6 | Aug 15, 2024 | Mar 27, 2024 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.2.7Upgrade Splunk Enterprise to version 9.3.5Upgrade Splunk Enterprise to version 9.1.10Upgrade Splunk Enterprise to version 9.4.3 | Jul 30, 2026 | Mar 27, 2024 |
| Suse | — | Upgrade libcurl-devel-docUpgrade libcurl4Upgrade libcurl-develUpgrade libcurl4-32bitUpgrade libcurl-mini4Upgrade curl-zsh-completionUpgrade curl | Oct 31, 2024 | Mar 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub