Patch for Insecure Database Query Vulnerability in Minder
CVE-2024-27916

7.1HIGH

Key Information:

Vendor

Stacklok

Status
Vendor
CVE Published:
21 March 2024

What is CVE-2024-27916?

A security vulnerability has been identified in the Minder software supply chain security platform that allows any authenticated user to access repository data irrespective of ownership or specific user permissions. Prior to version 0.0.33, the software's endpoints, such as GetRepositoryByName, DeleteRepositoryByName, and GetArtifactByName, permitted exploitation through improper validation of repository ownership. Any user with valid credentials could manipulate query parameters to access sensitive repository information, posing a significant risk to data security within the platform. The issue has since been addressed in version 0.0.33, which includes appropriate restrictions to safeguard against unauthorized data retrieval.

Affected Version(s)

minder < 0.0.33

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.