vulnerability
Alpine Linux: CVE-2024-0853: Improper Certificate Validation
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:P/A:N) | Feb 3, 2024 | Mar 21, 2024 | Dec 22, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Feb 3, 2024
Added
Mar 21, 2024
Modified
Dec 22, 2025
Description
curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to
the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.
the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.
Solution
alpine-linux-upgrade-curl
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.