libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.
History

Wed, 30 Jul 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Haxx
Haxx curl
Netapp
Netapp active Iq Unified Manager
Netapp bootstrap Os
Netapp h300s
Netapp h300s Firmware
Netapp h410s
Netapp h410s Firmware
Netapp h500s
Netapp h500s Firmware
Netapp h610c
Netapp h610c Firmware
Netapp h610s
Netapp h610s Firmware
Netapp h615c
Netapp h615c Firmware
Netapp h700s
Netapp h700s Firmware
Netapp hci Compute Node
Netapp ontap Select Deploy Administration Utility
CPEs cpe:2.3:a:haxx:curl:8.6.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h615c:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Haxx
Haxx curl
Netapp
Netapp active Iq Unified Manager
Netapp bootstrap Os
Netapp h300s
Netapp h300s Firmware
Netapp h410s
Netapp h410s Firmware
Netapp h500s
Netapp h500s Firmware
Netapp h610c
Netapp h610c Firmware
Netapp h610s
Netapp h610s Firmware
Netapp h615c
Netapp h615c Firmware
Netapp h700s
Netapp h700s Firmware
Netapp hci Compute Node
Netapp ontap Select Deploy Administration Utility

Thu, 14 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: curl

Published: 2024-03-27T07:56:41.158Z

Updated: 2025-02-13T17:39:51.599Z

Reserved: 2024-03-11T14:39:01.543Z

Link: CVE-2024-2379

cve-icon Vulnrichment

Updated: 2024-08-01T19:11:53.464Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-27T08:15:41.230

Modified: 2025-07-30T19:42:09.087

Link: CVE-2024-2379

cve-icon Redhat

Severity : Low

Publid Date: 2024-03-27T00:00:00Z

Links: CVE-2024-2379 - Bugzilla