Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-42966.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-42966
Upstream
Published
2024-03-27T08:15:41Z
Modified
2026-04-01T05:14:55.626199Z
Summary
CVE-2024-2379 affecting package cmake for versions less than 3.30.3-2
Details

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

References

Affected packages

Azure Linux:3 / cmake

Package

Name
cmake
Purl
pkg:rpm/azure-linux/cmake

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.30.3-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-42966.json"