Home

Description

An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.

PUBLISHED Reserved 2024-12-27 | Published 2024-12-27 | Updated 2025-03-24 | Assigner mitre

Problem types

CWE-295 Improper Certificate Validation

Product status

Default status
unaffected

Any version before 6.8.0
affected

References

tcpdf.org

github.com/tecnickcom/TCPDF/compare/6.7.8...6.8.0

github.com/...ommit/aab43ab0a824e956276141a28a24c7c0be20f554

cve.org (CVE-2024-56521)

nvd.nist.gov (CVE-2024-56521)

Download JSON