Fiche vulnérabilité
CVE-2020-8286 : faille élevée haxx libcurl (CVSS 7.5)
Description
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 14 déc. 2020
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- haxx libcurl
- fedoraproject fedora
- debian debian linux
- netapp clustered data ontap
- netapp hci management node
- netapp solidfire
- netapp hci bootstrap os
- netapp hci storage node firmware
- apple mac os x
- apple macos
- siemens simatic tim 1531 irc firmware
- siemens sinec infrastructure network services
- oracle communications billing and revenue management
- oracle communications cloud native core policy
- oracle essbase
- oracle peoplesoft enterprise peopletools
- splunk universal forwarder
Références
- Fiche CVE-2020-8286 sur le NVD (NIST)
- seclists.org/fulldisclosure/2021/Apr/50
- seclists.org/fulldisclosure/2021/Apr/51
- seclists.org/fulldisclosure/2021/Apr/54
- cert-portal.siemens.com/productcert/pdf/ssa-200951.pdf
- cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- curl.se/docs/CVE-2020-8286.html
- hackerone.com/reports/1048457
- lists.debian.org/debian-lts-announce/2020/12/msg00029.html
- lists.fedoraproject.org/archives/list/package…
- lists.fedoraproject.org/archives/list/package…
- security.gentoo.org/glsa/202012-14
- security.netapp.com/advisory/ntap-20210122-0007/
- support.apple.com/kb/HT212325
- support.apple.com/kb/HT212326
- support.apple.com/kb/HT212327