{"api_version":"1","generated_at":"2026-07-23T05:02:46+00:00","cve":"CVE-2017-2629","urls":{"html":"https://cve.report/CVE-2017-2629","api":"https://cve.report/api/cve/CVE-2017-2629.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-2629","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-2629"},"summary":{"title":"CVE-2017-2629","description":"curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or failure. It ends up always thinking there's valid proof, even when there is none or if the server doesn't support the TLS extension in question. This could lead to users not detecting when a server's certificate goes invalid or otherwise be mislead that the server is in a better shape than it is in reality. This flaw also exists in the command line tool (--cert-status).","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-07-27 19:29:00","updated_at":"2019-10-09 23:26:00"},"problem_types":["CWE-295"],"metrics":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2629","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2629","refsource":"CONFIRM","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"1425746 – (CVE-2017-2629) CVE-2017-2629 curl: SSL_VERIFYSTATUS ignored","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201703-04","name":"GLSA-201703-04","refsource":"GENTOO","tags":["Third Party Advisory"],"title":"cURL: Certificate validation error (GLSA 201703-04) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1037871","name":"1037871","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"cURL OCSP Stapling Verification Bug Lets Remote Users Bypass CURLOPT_SSL_VERIFYSTATUS Security Restrictions on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/96382","name":"96382","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"cURL/libcURL CVE-2017-2629 TLS Certificate Validation Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://curl.haxx.se/docs/adv_20170222.html","name":"https://curl.haxx.se/docs/adv_20170222.html","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"curl - SSL_VERIFYSTATUS ignored","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.tenable.com/security/tns-2017-09","name":"https://www.tenable.com/security/tns-2017-09","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"[R1] LCE 5.0.1 Fixes Two Third-party Library Vulnerabilities - Security Advisory | Tenable™","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-2629","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-2629","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"2629","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"haxx","cpe5":"curl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"2629","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"haxx","cpe5":"curl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2017-2629","qid":"500116","title":"Alpine Linux Security Update for curl"},{"cve":"CVE-2017-2629","qid":"503771","title":"Alpine Linux Security Update for curl"},{"cve":"CVE-2017-2629","qid":"710505","title":"Gentoo Linux cURL Certificate validation error Vulnerability (GLSA 201703-04)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2017-2629","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"curl","version":{"version_data":[{"version_value":"7.53.0"}]}}]},"vendor_name":"CURL"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or failure. It ends up always thinking there's valid proof, even when there is none or if the server doesn't support the TLS extension in question. This could lead to users not detecting when a server's certificate goes invalid or otherwise be mislead that the server is in a better shape than it is in reality. This flaw also exists in the command line tool (--cert-status)."}]},"impact":{"cvss":[[{"vectorString":"4.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","version":"3.0"}]]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-295"}]}]},"references":{"reference_data":[{"name":"96382","refsource":"BID","url":"http://www.securityfocus.com/bid/96382"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2629","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2629"},{"name":"1037871","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1037871"},{"name":"https://www.tenable.com/security/tns-2017-09","refsource":"CONFIRM","url":"https://www.tenable.com/security/tns-2017-09"},{"name":"https://curl.haxx.se/docs/adv_20170222.html","refsource":"CONFIRM","url":"https://curl.haxx.se/docs/adv_20170222.html"},{"name":"GLSA-201703-04","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201703-04"}]}},"nvd":{"publishedDate":"2018-07-27 19:29:00","lastModifiedDate":"2019-10-09 23:26:00","problem_types":["CWE-295"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*","versionEndExcluding":"7.53.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"2629","Ordinal":"98768","Title":"CVE-2017-2629","CVE":"CVE-2017-2629","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"2629","Ordinal":"1","NoteData":"curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or failure. It ends up always thinking there's valid proof, even when there is none or if the server doesn't support the TLS extension in question. This could lead to users not detecting when a server's certificate goes invalid or otherwise be mislead that the server is in a better shape than it is in reality. This flaw also exists in the command line tool (--cert-status).","Type":"Description","Title":null},{"CveYear":"2017","CveId":"2629","Ordinal":"2","NoteData":"2018-07-27","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"2629","Ordinal":"3","NoteData":"2018-07-28","Type":"Other","Title":"Modified"}]}}}