Improper Certificate Validation in cURL - CVE-2024-2379

 

Improper Certificate Validation in cURL - CVE-2024-2379

Published: March 27, 2024


Vulnerability identifier: #VU87848
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-2379
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to improper certificate validation for a QUIC connection under certain conditions, when built to use wolfSSL. A remote attacker can force the application to ignore the certificate and perform MitM attack.

Successful exploitation of the vulnerability requires that the used wolfSSL library was built with the OPENSSL_COMPATIBLE_DEFAULTS symbol set, which is not set for the recommended configure --enable-curl builds.


Affected software

cURL
Oracle Solaris
PowerSC
macOS
Slackware Linux
LANTIME Operating System Firmware (LTOS)
webMethods Managed File Transfer
Storage Copy Data Management
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
SecurityCenter
Data Lakehouse
IBM QRadar WinCollect Agent
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
curl
jbcs-httpd24-curl (Red Hat package)
JBoss Core Services

How to mitigate CVE-2024-2379

Install updates from vendor's website.

cURL - update to 8.7.0
Oracle Solaris - update to 11.4 SRU 71
LANTIME Operating System Firmware (LTOS) - update to 7.08.010
macOS - addressed in versions 12.7.6 21H1320, 13.6.8 22G820, 14.6 23G80
SecurityCenter - update to SC-202408.1
Data Lakehouse - update to 1.3.0.0
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.20-4.el7jbcs, 1.3.20-4.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-37.el7jbcs, 1.15.19-37.el8jbcs
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.43.0-13.el7jbcs, 1.43.0-13.el8jbcs
Storage Copy Data Management - update to 2.2.25.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-6.el7jbcs, 2.4.24-6.el8jbcs
JBoss Core Services - update to 2.4.57 SP4
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-10.el7jbcs, 2.4.57-10.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-36.el7jbcs, 2.9.3-36.el8jbcs
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
curl - update to 8.7.1
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.7.1-2.el7jbcs, 8.7.1-2.el8jbcs
IBM QRadar WinCollect Agent - update to 10.1.11

External References

Related Security Bulletins