CVE-2024-8096

CVE Information
CVE ID
CVE-2024-8096
Severity
MEDIUM CVSS 6.5
Publish Date
2024-09-11
Description

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.

Collection Date
2026-02-05
Impact Summary
Affected Hosts 3
Related Incidents 0
Related Alerts 0
Affected Hosts (3)
Hostname OS Type Severity Total CVEs
in-bridge-40 LINUX CRITICAL 396
inbridge-ubt-24 LINUX CRITICAL 2336
inbridge-42 LINUX CRITICAL 148