CVE-2024-2004Patch(apple / bootstrap_os)

LOWCVSS 3.5 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple bootstrap_os systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.se The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-436

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bootstrap_os
  • curl
  • fedora
  • h300s

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
bootstrap_oscurlfedorah300sh300s_firmwareh410sh410s_firmwareh500sh500s_firmwareh700s

4 versions affected across 15 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-11: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-11: 105-11
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Inqodo@inqodo
    Patch

    Code's haunted. Critical curl vuln (CVE-2024-2004) lets attackers execute remote code through HTTP requests. Your SaaS is bleeding. Patch now or get pwned. Mythos team just dropped the nuclear option. https://t.co/T3Z5Jry260

    Post summary

    The tweet highlights a critical Remote Code Execution flaw in curl (CVE-2024-2004) and urges immediate patching, but does not provide PoC, exploit code or evidence of active exploitation.

    0000082
    16 followersView on X
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
OSfedoraprojectfedora39--
OSfedoraprojectfedora40--
Apphaxxcurl---
OSnetappbootstrap_os---
HWnetapph300s---
OSnetapph300s_firmware---
HWnetapph410s---
OSnetapph410s_firmware---
HWnetapph500s---
OSnetapph500s_firmware---
HWnetapph700s---
OSnetapph700s_firmware---
HWnetapphci_compute_node---
Appnetappontap9--
Appnetappontap_select_deploy_administration_utility---

Explore more