A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 08 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Csutils
Csutils csmock |
|
| CPEs | cpe:2.3:a:csutils:csmock:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Csutils
Csutils csmock |
Wed, 28 May 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Status: PUBLISHED
Assigner: fedora
Published: 2024-04-10T10:14:47.671Z
Updated: 2025-11-04T22:05:38.828Z
Reserved: 2024-03-07T00:03:13.257Z
Link: CVE-2024-2243
Updated: 2025-11-04T22:05:38.828Z
Status : Modified
Published: 2024-04-10T11:15:49.443
Modified: 2025-11-04T22:16:00.140
Link: CVE-2024-2243