Vulnerability Details CVE-2024-2243
A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 15.9%
CVSS Severity
CVSS v3 Score 7.6
Products affected by CVE-2024-2243
-
cpe:2.3:a:csutils:csmock:1.0.0
-
cpe:2.3:a:csutils:csmock:1.0.1
-
cpe:2.3:a:csutils:csmock:1.0.10
-
cpe:2.3:a:csutils:csmock:1.0.11
-
cpe:2.3:a:csutils:csmock:1.0.2
-
cpe:2.3:a:csutils:csmock:1.0.3
-
cpe:2.3:a:csutils:csmock:1.0.4
-
cpe:2.3:a:csutils:csmock:1.0.5
-
cpe:2.3:a:csutils:csmock:1.0.6
-
cpe:2.3:a:csutils:csmock:1.0.7
-
cpe:2.3:a:csutils:csmock:1.0.8
-
cpe:2.3:a:csutils:csmock:1.0.9
-
cpe:2.3:a:csutils:csmock:1.1.0
-
cpe:2.3:a:csutils:csmock:1.1.1
-
cpe:2.3:a:csutils:csmock:1.2.0
-
cpe:2.3:a:csutils:csmock:1.2.1
-
cpe:2.3:a:csutils:csmock:1.2.2
-
cpe:2.3:a:csutils:csmock:1.2.3
-
cpe:2.3:a:csutils:csmock:1.3.0
-
cpe:2.3:a:csutils:csmock:1.3.1
-
cpe:2.3:a:csutils:csmock:1.3.2
-
cpe:2.3:a:csutils:csmock:1.4.0
-
cpe:2.3:a:csutils:csmock:1.4.1
-
cpe:2.3:a:csutils:csmock:1.5.0
-
cpe:2.3:a:csutils:csmock:1.5.1
-
cpe:2.3:a:csutils:csmock:1.6.0
-
cpe:2.3:a:csutils:csmock:1.6.1
-
cpe:2.3:a:csutils:csmock:1.6.2
-
cpe:2.3:a:csutils:csmock:1.7.0
-
cpe:2.3:a:csutils:csmock:1.7.1
-
cpe:2.3:a:csutils:csmock:1.7.2
-
cpe:2.3:a:csutils:csmock:1.8.0
-
cpe:2.3:a:csutils:csmock:1.8.1
-
cpe:2.3:a:csutils:csmock:1.8.2
-
cpe:2.3:a:csutils:csmock:1.8.3
-
cpe:2.3:a:csutils:csmock:1.9.0
-
cpe:2.3:a:csutils:csmock:1.9.1
-
cpe:2.3:a:csutils:csmock:1.9.2
-
cpe:2.3:a:csutils:csmock:2.0.0
-
cpe:2.3:a:csutils:csmock:2.0.1
-
cpe:2.3:a:csutils:csmock:2.0.2
-
cpe:2.3:a:csutils:csmock:2.0.3
-
cpe:2.3:a:csutils:csmock:2.0.4
-
cpe:2.3:a:csutils:csmock:2.1.0
-
cpe:2.3:a:csutils:csmock:2.1.1
-
cpe:2.3:a:csutils:csmock:2.2.0
-
cpe:2.3:a:csutils:csmock:2.2.1
-
cpe:2.3:a:csutils:csmock:2.3.0
-
cpe:2.3:a:csutils:csmock:2.4.0
-
cpe:2.3:a:csutils:csmock:2.5.0
-
cpe:2.3:a:csutils:csmock:2.6.0
-
cpe:2.3:a:csutils:csmock:2.7.0
-
cpe:2.3:a:csutils:csmock:2.7.1
-
cpe:2.3:a:csutils:csmock:2.8.0
-
cpe:2.3:a:csutils:csmock:2.9.0
-
cpe:2.3:a:csutils:csmock:3.0.0
-
cpe:2.3:a:csutils:csmock:3.1.0
-
cpe:2.3:a:csutils:csmock:3.2.0
-
cpe:2.3:a:csutils:csmock:3.3.0
-
cpe:2.3:a:csutils:csmock:3.3.1
-
cpe:2.3:a:csutils:csmock:3.3.2
-
cpe:2.3:a:csutils:csmock:3.3.3
-
cpe:2.3:a:csutils:csmock:3.3.4
-
cpe:2.3:a:csutils:csmock:3.3.5
-
cpe:2.3:a:csutils:csmock:3.4.0
-
cpe:2.3:a:csutils:csmock:3.4.1
-
cpe:2.3:a:csutils:csmock:3.4.2
-
cpe:2.3:a:csutils:csmock:3.5.0
-
cpe:2.3:a:csutils:csmock:3.5.1
-
cpe:2.3:a:csutils:csmock:3.5.2