Cachi2 is a command-line interface tool that pre-fetches a project's dependencies to aid in making the project's build process network-isolated. Prior to version 0.14.0, secrets may be shown in logs when an unhandled exception is triggered because the tool is logging locals of each function. This may uncover secrets if tool used in CI/build pipelines as it's the main use case. Version 0.14.0 contains a patch for the issue. No known workarounds are available.
History

Tue, 19 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Containerbuildsystem
Containerbuildsystem cachi2
CPEs cpe:2.3:a:containerbuildsystem:cachi2:*:*:*:*:*:*:*:*
Vendors & Products Containerbuildsystem
Containerbuildsystem cachi2
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 19 Nov 2024 15:45:00 +0000

Type Values Removed Values Added
Description Cachi2 is a command-line interface tool that pre-fetches a project's dependencies to aid in making the project's build process network-isolated. Prior to version 0.14.0, secrets may be shown in logs when an unhandled exception is triggered because the tool is logging locals of each function. This may uncover secrets if tool used in CI/build pipelines as it's the main use case. Version 0.14.0 contains a patch for the issue. No known workarounds are available.
Title cachi2 allows traceback prints locals
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-19T15:32:26.579Z

Updated: 2024-11-19T16:24:58.503Z

Reserved: 2024-11-14T15:05:46.766Z

Link: CVE-2024-52582

cve-icon Vulnrichment

Updated: 2024-11-19T16:24:53.947Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-19T16:15:20.207

Modified: 2024-11-19T21:57:32.967

Link: CVE-2024-52582

cve-icon Redhat

No data.