A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-27199 A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Nov 2025 22:30:00 +0000


Tue, 04 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 19:30:00 +0000


Fri, 08 Aug 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Csutils
Csutils csmock
CPEs cpe:2.3:a:csutils:csmock:*:*:*:*:*:*:*:*
Vendors & Products Csutils
Csutils csmock

Wed, 28 May 2025 17:00:00 +0000

Type Values Removed Values Added
References

Thu, 22 May 2025 02:45:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2025-11-04T22:05:38.828Z

Reserved: 2024-03-07T00:03:13.257Z

Link: CVE-2024-2243

cve-icon Vulnrichment

Updated: 2025-11-04T22:05:38.828Z

cve-icon NVD

Status : Modified

Published: 2024-04-10T11:15:49.443

Modified: 2025-11-04T22:16:00.140

Link: CVE-2024-2243

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-03-20T00:00:00Z

Links: CVE-2024-2243 - Bugzilla

cve-icon OpenCVE Enrichment

No data.