Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-9681— HSTS subdomain overwrites parent cache entry

Quick assessment

Affected
curl curl
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

curl是cURL开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 7.74.0至8.10.1版本存在安全漏洞,该漏洞源于当curl被要求使用HTTP严格传输安全(HSTS)时,子域名的过期时间会覆盖父域名的缓存条目。

AI Predicted 5.3 Difficulty: Moderate EPSS 1.99% · P80

Possible ATT&CK Techniques 1 AI

T1071 · Application Layer Protocol
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-9681

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
HSTS subdomain overwrites parent cache entry
Source: CVE Program / CVE List V5
Vulnerability Description
When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise intended. This affects curl using applications that enable HSTS and use URLs with the insecure `HTTP://` scheme and perform transfers with hosts like `x.example.com` as well as `example.com` where the first host is a subdomain of the second host. (The HSTS cache either needs to have been populated manually or there needs to have been previous HTTPS accesses done as the cache needs to have entries for the domains involved to trigger this problem.) When `x.example.com` responds with `Strict-Transport-Security:` headers, this bug can make the subdomain's expiry timeout *bleed over* and get set for the parent domain `example.com` in curl's HSTS cache. The result of a triggered bug is that HTTP accesses to `example.com` get converted to HTTPS for a different period of time than what was asked for by the origin server. If `example.com` for example stops supporting HTTPS at its expiry time, curl might then fail to access `http://example.com` until the (wrongly set) timeout expires. This bug can also expire the parent's entry *earlier*, thus making curl inadvertently switch back to insecure HTTP earlier than otherwise intended.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
curl 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
curl是cURL开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 7.74.0至8.10.1版本存在安全漏洞,该漏洞源于当curl被要求使用HTTP严格传输安全(HSTS)时,子域名的过期时间会覆盖父域名的缓存条目。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
curl curl 8.10.1 ~ 8.10.1 -

II. Public POCs for CVE-2024-9681

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-9681

请登录查看更多情报信息。

Vendor Advisories for CVE-2024-9681 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2024-9681

No comments yet


Leave a comment