by @Smartkeyss
10 Jun 2024

TLS certificate check bypass cURL with mbedTLS - (CVE-2024-2466)

by @Smartkeyss
10 Jun 2024

TLS certificate check bypass cURL with mbedTLS - (CVE-2024-2466)

CVEs

N/A Severity

PoC video

Summary

libcurl with mbedTLS skips TLS certificate checks for IP address connections, bypassing security for all TLS protocols (HTTPS, FTPS, IMAPS, etc.).

Description

users/photos/clsevlral8gef1hon15grbvup.jpg

@Smartkeyss

29 posts

I am just curious 😊 I use simple words to explain complicated things.

Total vcoins

83.7K

Comments (0)