Improper Certificate Validation in cURL - CVE-2024-2379
Published: March 27, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation for a QUIC connection under certain conditions, when built to use wolfSSL. A remote attacker can force the application to ignore the certificate and perform MitM attack.
Successful exploitation of the vulnerability requires that the used wolfSSL library was built with the OPENSSL_COMPATIBLE_DEFAULTS symbol set, which is not set for the recommended configure --enable-curl builds.
Affected software
Oracle Solaris
PowerSC
macOS
Slackware Linux
LANTIME Operating System Firmware (LTOS)
webMethods Managed File Transfer
Storage Copy Data Management
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
SecurityCenter
Data Lakehouse
IBM QRadar WinCollect Agent
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
curl
jbcs-httpd24-curl (Red Hat package)
JBoss Core Services
How to mitigate CVE-2024-2379
Oracle Solaris - update to 11.4 SRU 71
LANTIME Operating System Firmware (LTOS) - update to 7.08.010
macOS - addressed in versions 12.7.6 21H1320, 13.6.8 22G820, 14.6 23G80
SecurityCenter - update to SC-202408.1
Data Lakehouse - update to 1.3.0.0
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.20-4.el7jbcs, 1.3.20-4.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-37.el7jbcs, 1.15.19-37.el8jbcs
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.43.0-13.el7jbcs, 1.43.0-13.el8jbcs
Storage Copy Data Management - update to 2.2.25.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-6.el7jbcs, 2.4.24-6.el8jbcs
JBoss Core Services - update to 2.4.57 SP4
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-10.el7jbcs, 2.4.57-10.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-36.el7jbcs, 2.9.3-36.el8jbcs
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
curl - update to 8.7.1
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.7.1-2.el7jbcs, 8.7.1-2.el8jbcs
IBM QRadar WinCollect Agent - update to 10.1.11
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Slackware Linux update for curl
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Multiple vulnerabilities in PowerSC
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Tenable Security Center
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- Oracle Solaris update for thrid-party components
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Dell Data Lakehouse System software update for third-party components
- Multiple vulnerabilities in IBM webMethods Managed File Transfer
- Meinberg LANTIME firmware update for third-party components (April 2024)
- Multiple vulnerabilities in IBM Storage Protect Backup-Archive Client, IBM Storage Protect for Virtual Environments and IBM Storage Protect for Space Management