A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2024-04-10T10:14:47.671Z

Updated: 2024-08-01T19:03:39.111Z

Reserved: 2024-03-07T00:03:13.257Z

Link: CVE-2024-2243

cve-icon Vulnrichment

Updated: 2024-08-01T19:03:39.111Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-10T11:15:49.443

Modified: 2024-11-21T09:09:20.247

Link: CVE-2024-2243

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-03-20T00:00:00Z

Links: CVE-2024-2243 - Bugzilla