Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-52582

Опубликовано: 19 нояб. 2024
Источник: nvd
CVSS3: 4.7
EPSS Низкий

Описание

Cachi2 is a command-line interface tool that pre-fetches a project's dependencies to aid in making the project's build process network-isolated. Prior to version 0.14.0, secrets may be shown in logs when an unhandled exception is triggered because the tool is logging locals of each function. This may uncover secrets if tool used in CI/build pipelines as it's the main use case. Version 0.14.0 contains a patch for the issue. No known workarounds are available.

EPSS

Процентиль: 23%
0.00076
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-497

EPSS

Процентиль: 23%
0.00076
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-497