Improper validation of certificate with host mismatch in cURL - CVE-2024-2466

 

Improper validation of certificate with host mismatch in cURL - CVE-2024-2466

Published: March 27, 2024


Vulnerability identifier: #VU87852
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-2466
CWE-ID: CWE-297
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
cURL
Oracle Solaris
Gentoo Linux
PowerSC
IBM AIX
macOS
Slackware Linux
LANTIME Operating System Firmware (LTOS)
webMethods Managed File Transfer
Storage Copy Data Management
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
SecurityCenter
Data Lakehouse
IBM QRadar WinCollect Agent
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
net-misc/curl
curl
jbcs-httpd24-curl (Red Hat package)
JBoss Core Services

Detailed vulnerability description

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to libcurl does not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. A remote attacker force the application to completely skip the certificate check and perform MitM attack.


How to mitigate CVE-2024-2466

Install updates from vendor's website.

Sources