Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-35183

Опубликовано: 15 мая 2024
Источник: nvd
CVSS3: 4.4
EPSS Низкий

Описание

wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a local user’s GitHub token to be sent to remote servers other than github.com. Most git-dependent functionality in wolfictl relies on its own git package, which contains centralized logic for implementing interactions with git repositories. Some of this functionality requires authentication in order to access private repositories. A central function GetGitAuth looks for a GitHub token in the environment variable GITHUB_TOKEN and returns it as an HTTP basic auth object to be used with the github.com/go-git/go-git/v5 library. Most callers (direct or indirect) of GetGitAuth use the token to authenticate to github.com only; however, in some cases callers were passing this authentication without checking that the remote git repository was hosted on github.com. This behavior has existed in one form or another since commit 0d06e1578300327c212dda26a5ab31d09352b9

EPSS

Процентиль: 17%
0.00054
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 4.4
github
больше 1 года назад

wolfictl leaks GitHub tokens to remote non-GitHub git servers

EPSS

Процентиль: 17%
0.00054
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-552