CVE-2024-8096: Debian Linux
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.
Affected products
- Debian Debian Linux: version 11.0 only
- Haxx Curl: from 7.41.0, before 8.10.0 (fixed in 8.10.0)
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Bootstrap OS: affected versions not specified
- Netapp h300s Firmware: affected versions not specified
- Netapp h410s Firmware: affected versions not specified
- Netapp h500s Firmware: affected versions not specified
- Netapp h700s Firmware: affected versions not specified
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
- Netapp Ontap Tools: version 10 only
Published 2024-09-11. Last modified 2026-06-17.