libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).
History

Fri, 23 Aug 2024 20:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Fri, 23 Aug 2024 19:30:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: curl

Published: 2024-03-27T07:58:24.520Z

Updated: 2024-08-23T18:46:47.386Z

Reserved: 2024-03-14T17:21:59.730Z

Link: CVE-2024-2466

cve-icon Vulnrichment

Updated: 2024-08-19T07:47:51.205Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-27T08:15:41.343

Modified: 2024-11-21T09:09:48.847

Link: CVE-2024-2466

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-03-27T00:00:00Z

Links: CVE-2024-2466 - Bugzilla