Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-31455

Опубликовано: 09 апр. 2024
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

Minder by Stacklok is an open source software supply chain security platform. A refactoring in commit 5c381cf added the ability to get GitHub repositories registered to a project without specifying a specific provider. Unfortunately, the SQL query for doing so was missing parenthesis, and would select a random repository. This issue is patched in pull request 2941. As a workaround, revert prior to 5c381cf, or roll forward past 2eb94e7.

EPSS

Процентиль: 56%
0.00343
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
github
почти 2 года назад

Minder GetRepositoryByName data leak

EPSS

Процентиль: 56%
0.00343
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200