Low Severity Bug in curl Affects Protocol Selection
CVE-2024-2004
What is CVE-2024-2004?
A logic flaw in the Curl command line tool allows certain commands to inadvertently enable disabled protocols. When a user configures the protocol selection parameter to disable all available protocols without defining any alternatives, the system retains a default set of protocols due to an oversight in the implementation. This could lead to the execution of requests using a plaintext protocol that the user intended to disable, although such scenarios are largely impractical in everyday use. The Curl security team has evaluated the potential implications and noted that this is not likely to pose a significant threat in common operating environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
curl 8.6.0
curl 8.5.0
curl 8.4.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
