CVE-2024-2379
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.
MEDIUM · CVSS 6.3
EPSS 0.00205
Schedule remediation
- Public exploit or PoC is available
Sigma rules15
YARA rules0