Medium severity6.3NVD Advisory· Published Mar 27, 2024· Updated Jun 17, 2026
CVE-2024-2379
CVE-2024-2379
Description
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- osv-coords16 versionspkg:apk/chainguard/curlpkg:apk/chainguard/curl-devpkg:apk/chainguard/curl-docpkg:apk/chainguard/curl-oci-entrypointpkg:apk/chainguard/curl-staticpkg:apk/chainguard/libcurl4pkg:apk/chainguard/libcurl-openssl4pkg:apk/wolfi/curlpkg:apk/wolfi/curl-devpkg:apk/wolfi/curl-docpkg:apk/wolfi/curl-oci-entrypointpkg:apk/wolfi/curl-staticpkg:apk/wolfi/libcurl4pkg:apk/wolfi/libcurl-openssl4pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Micro%206.0
< 8.7.1-r0+ 15 more
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-1.1
- (no CPE)range: < 8.6.0-3.1
Patches
Vulnerability mechanics
References
11- hackerone.com/reports/2410774nvdExploitIssue TrackingThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/18nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/19nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/20nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2024/03/27/2nvdMailing ListThird Party Advisory
- curl.se/docs/CVE-2024-2379.htmlnvdVendor Advisory
- curl.se/docs/CVE-2024-2379.jsonnvdVendor Advisory
- security.netapp.com/advisory/ntap-20240531-0001/nvdThird Party Advisory
- support.apple.com/kb/HT214118nvdRelease NotesVendor Advisory
- support.apple.com/kb/HT214119nvdRelease NotesVendor Advisory
- support.apple.com/kb/HT214120nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.