Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-27916

Опубликовано: 21 мар. 2024
Источник: nvd
CVSS3: 7.1
CVSS3: 4.3
EPSS Низкий

Описание

Minder is a software supply chain security platform. Prior to version 0.0.33, a Minder user can use the endpoints GetRepositoryByName, DeleteRepositoryByName, and GetArtifactByName to access any repository in the database, irrespective of who owns the repo and any permissions present. The database query checks by repo owner, repo name and provider name (which is always github). These query values are not distinct for the particular user - as long as the user has valid credentials and a provider, they can set the repo owner/name to any value they want and the server will return information on this repo. Version 0.0.33 contains a patch for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lfprojects:minder:*:*:*:*:*:go:*:*
Версия до 0.0.33 (исключая)

EPSS

Процентиль: 39%
0.00177
Низкий

7.1 High

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 7.1
github
почти 2 года назад

`GetRepositoryByName`, `DeleteRepositoryByName` and `GetArtifactByName` allow access of arbitrary repositories in Minder by any authenticated user

EPSS

Процентиль: 39%
0.00177
Низкий

7.1 High

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-285