Authentication Bypass in CodeChecker by Ericsson
CVE-2024-10081

Currently unrated

Key Information:

Vendor

Ericsson

Vendor
CVE Published:
6 November 2024

What is CVE-2024-10081?

An authentication bypass vulnerability has been identified in CodeChecker, an analyzer tooling and viewer extension for the Clang Static Analyzer and Clang Tidy. This vulnerability allows unauthorized access to vital API endpoints, permitting users to perform actions such as adding, editing, and removing products without proper credentials. The affected endpoints enable superuser capabilities, putting system integrity at risk when the API URL ends with 'Authentication'. This issue impacts all versions through 6.24.1.

References

EPSS Score

57% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

.
CVE-2024-10081 : Authentication Bypass in CodeChecker by Ericsson