CVE-2020-8286

HIGH

libcurl 7.41.0-7.73.0 - Improper Certificate Validation via OCSP Response

Title source: llm
STIX 2.1

Description

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

References (19)

Core 19
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1048457
Vendor Advisory x_refsource_misc
https://curl.se/docs/CVE-2020-8286.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202012-14
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4881
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Apr/51
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Apr/50
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Apr/54
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuApr2021.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210122-0007/
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212325
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212326
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212327
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-200951.pdf
Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html
Patch, Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf

Scores

CVSS v3 7.5
EPSS 0.0029
EPSS Percentile 52.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (22)
apple/mac_os_x 10.14.6 (11 CPE variants)
apple/mac_os_x 10.15.7 (4 CPE variants)
apple/mac_os_x < 10.14.6
apple/macos 11.0 - 11.3
debian/debian_linux 9.0
debian/debian_linux 10.0
fedoraproject/fedora 32
fedoraproject/fedora 33
haxx/libcurl 7.41.0 - 7.74.0
netapp/clustered_data_ontap
... and 12 more
Published Dec 14, 2020
Tracked Since Feb 18, 2026