CVE-2024-52582 Vulnerability Details

  /     /     /  

CVE-2024-52582 Metadata Quick Info

CVE Published: 19/11/2024 | CVE Updated: 19/11/2024 | CVE Year: 2024
Source: GitHub_M | Vendor: containerbuildsystem | Product: cachi2
Status : PUBLISHED

CVE-2024-52582 Description

Cachi2 is a command-line interface tool that pre-fetches a project\'s dependencies to aid in making the project\'s build process network-isolated. Prior to version 0.14.0, secrets may be shown in logs when an unhandled exception is triggered because the tool is logging locals of each function. This may uncover secrets if tool used in CI/build pipelines as it\'s the main use case. Version 0.14.0 contains a patch for the issue. No known workarounds are available.

Metrics

CVSS Version: 3.1 | Base Score: 4.7 MEDIUM
Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* NONE
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* NONE
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-497
CWE Name: CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
Source: containerbuildsystem

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).