Description
Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploykeys where attackers can guess the key to get write access to the registry. User must upgrade to 0.9.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53435 | Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploykeys where attackers can guess the key to get write access to the registry. User must upgrade to 0.9.2. |
References
History
Tue, 31 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Dec 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploykeys where attackers can guess the key to get write access to the registry. User must upgrade to 0.9.2. | |
| Title | Tapir allows DeployKey exposure | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-31T15:52:36.405Z
Reserved: 2024-12-30T16:08:56.067Z
Link: CVE-2024-56802
Updated: 2024-12-31T15:52:28.468Z
Status : Received
Published: 2024-12-31T16:15:28.240
Modified: 2024-12-31T16:15:28.240
Link: CVE-2024-56802
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD